PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107810 0xJacky CVE debrief

CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to inject configuration or cause denial of service through crafted backups. Affected versions (2.0.0-2.4.0) require patching or mitigation to prevent exploitation. The vulnerability is fixed in version 2.5.0. Nginx UI administrators, security teams, and users with access to backup and restore functionality should assess exposure and apply patches or mitigations as needed. This issue involves the internal/backup/restore.go file, which extracts inner archives before applying restore flags and permits symlinks targeting the live Nginx configuration path.

Vendor
0xJacky
Product
nginx-ui
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Nginx UI administrators, security teams, and users with access to backup and restore functionality should assess exposure and apply patches or mitigations as needed. This includes reviewing and updating backup and restore procedures, verifying user access controls, and monitoring Nginx UI configuration and logs for suspicious activity. Additionally, affected operators and platform administrators should prioritize patching or mitigating this vulnerability.

Why it matters

CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to inject configuration or cause denial of service through crafted backups. Affected versions (2.0.0-2.4.0) require patching or mitigation to prevent exploitation.

  • Potential persistent configuration injection
  • Possible denial of service through modified configuration files
  • Requires verification of backup and restore procedures
  • Necessitates review of user access controls for backup functionality

Technical summary

Nginx UI 2.0.0-2.4.0 contains a vulnerability in the backup restore functionality. An authenticated user can craft a backup that creates a symlink in the staging tree, allowing injection of configuration or denial of service when modified files are consumed. The issue is caused by the internal/backup/restore.go file, which extracts inner archives before applying the restore_nginx and restore_nginx_ui flags. This can persistently inject configuration or cause denial of service when the modified files are later consumed. Fixed in version 2.5.0.

Defensive priority

High priority for Nginx UI administrators and security teams

Recommended defensive actions

  • Review and apply vendor-provided patch (version 2.5.0) if using affected Nginx UI versions (2.0.0 - 2.4.0)
  • Restrict backup restore access to trusted users and validate backup files before restoration
  • Monitor Nginx UI configuration and logs for suspicious activity
  • Verify backup and restore procedures to prevent unauthorized configuration changes
  • Conduct a thorough review of user access controls for backup functionality
  • Implement additional monitoring for potential configuration injection or denial of service
  • Track and document changes to Nginx UI configuration and backup processes

Evidence notes

Official CVE Program record and NVD vulnerability detail page provide limited information on affected versions and exploitation. Vendor documentation and source code review are necessary for further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107810 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107810

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107810 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107810

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107810.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p8v3-89rh-jxc7

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef9f7

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.