PatchSiren cyber security CVE debrief
CVE-2026-107810 0xJacky CVE debrief
CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to inject configuration or cause denial of service through crafted backups. Affected versions (2.0.0-2.4.0) require patching or mitigation to prevent exploitation. The vulnerability is fixed in version 2.5.0. Nginx UI administrators, security teams, and users with access to backup and restore functionality should assess exposure and apply patches or mitigations as needed. This issue involves the internal/backup/restore.go file, which extracts inner archives before applying restore flags and permits symlinks targeting the live Nginx configuration path.
- Vendor
- 0xJacky
- Product
- nginx-ui
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Nginx UI administrators, security teams, and users with access to backup and restore functionality should assess exposure and apply patches or mitigations as needed. This includes reviewing and updating backup and restore procedures, verifying user access controls, and monitoring Nginx UI configuration and logs for suspicious activity. Additionally, affected operators and platform administrators should prioritize patching or mitigating this vulnerability.
Why it matters
CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to inject configuration or cause denial of service through crafted backups. Affected versions (2.0.0-2.4.0) require patching or mitigation to prevent exploitation.
- Potential persistent configuration injection
- Possible denial of service through modified configuration files
- Requires verification of backup and restore procedures
- Necessitates review of user access controls for backup functionality
Technical summary
Nginx UI 2.0.0-2.4.0 contains a vulnerability in the backup restore functionality. An authenticated user can craft a backup that creates a symlink in the staging tree, allowing injection of configuration or denial of service when modified files are consumed. The issue is caused by the internal/backup/restore.go file, which extracts inner archives before applying the restore_nginx and restore_nginx_ui flags. This can persistently inject configuration or cause denial of service when the modified files are later consumed. Fixed in version 2.5.0.
Defensive priority
High priority for Nginx UI administrators and security teams
Recommended defensive actions
- Review and apply vendor-provided patch (version 2.5.0) if using affected Nginx UI versions (2.0.0 - 2.4.0)
- Restrict backup restore access to trusted users and validate backup files before restoration
- Monitor Nginx UI configuration and logs for suspicious activity
- Verify backup and restore procedures to prevent unauthorized configuration changes
- Conduct a thorough review of user access controls for backup functionality
- Implement additional monitoring for potential configuration injection or denial of service
- Track and document changes to Nginx UI configuration and backup processes
Evidence notes
Official CVE Program record and NVD vulnerability detail page provide limited information on affected versions and exploitation. Vendor documentation and source code review are necessary for further verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107810 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107810
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107810 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107810
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107810.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p8v3-89rh-jxc7
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef9f7
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.