A critical remote code execution flaw has been disclosed in the Nginx UI project (CVE-2026-107806), with a working proof-of-concept exploit published. The vulnerability enables authenticated attackers to execute arbitrary code on affected servers, potentially giving them full administrative control over the underlying system. The CVSS score is 9.4 (Critical, CVSSv4).
The advisory notes that versions of Nginx UI from 2.3.8 up to, but not including, 2.5.0 are affected, and the issue stems from a trust-boundary failure during the system backup restoration process. While the public disclosure raises risk, the article states there is no confirmed exploitation in the wild at this time.
How the attack works hinges on an authenticated administrator initiating a secure session and then the attacker uploading a forged configuration backup containing a malicious application manifest. The backup signing key is derived from attacker-supplied data, allowing the payload to be decrypted and the system to blindly accept the file, overwriting protected application settings.
By injecting malicious operating-system commands into specific configuration parameters, the attacker can execute commands within the application’s runtime context, which typically has elevated privileges. Mitigation is to upgrade to Nginx UI version 2.5.0 or later, which adds strict validation for restored configuration files and authenticates backups with a server-held secret. Administrators should apply the vendor advisory promptly to reduce exposure.