/Vulnerability Library

Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure

CVE-2026-42221
Verified

Description

Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated access to /api/install during first-run setup, letting remote attackers claim the initial admin account, exploit requires attacker to access the service before legitimate operator.

Severity

High

CVSS Score

8.1

Exploit Probability

2%

Affected Product

nginx-ui

Published Date

September 1, 2026

Template Author

str4k3r

CVE-2026-42221.yaml
8.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42221
CWE ID:
cwe-306

References

https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h27v-ph7w-m9fphttps://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8https://nvd.nist.gov/vuln/detail/CVE-2026-42221

Remediation Steps

Upgrade to version 2.3.8 or later.