CVE-2026-42221 Details
Description
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality in transit; it does not authenticate who is allowed to perform installation. A remote attacker who reaches the service before the legitimate operator can set the admin email, username, and password, causing permanent initial-instance takeover. This issue has been patched in version 2.3.8.
A vulnerability in Nginx UI versions 2.0.0 prior to 2.3.8 allows an unauthenticated network attacker to take over the initial administrator account on a new Nginx UI instance during the first-run setup. The public /api/install endpoint can be accessed without authentication, and while the request-encryption process protects payload confidentiality in transit, it does not verify who is authorized to perform the installation. An attacker who accesses the service before the legitimate operator can manipulate the admin email, username, and password, leading to permanent takeover of the initial admin account. This vulnerability has been patched in version 2.3.8.
Users can update to Nginx UI version 2.3.8 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h27v-ph7w-m9fp | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8 | [email protected] | Release Notes |
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h27v-ph7w-m9fp | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nginxui nginx ui | >= 2.0.0, < 2.3.8 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |