Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure
CVE-2026-42221
Verified
Description
Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated access to /api/install during first-run setup, letting remote attackers claim the initial admin account, exploit requires attacker to access the service before legitimate operator.
Severity
High
CVSS Score
8.1
Exploit Probability
2%
Affected Product
nginx-ui
Published Date
September 1, 2026
Template Author
str4k3r
CVE-2026-42221.yaml
8.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42221
CWE ID:
cwe-306
Remediation Steps
Upgrade to version 2.3.8 or later.