PatchSiren cyber security CVE debrief
CVE-2026-77180 F5 CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:23.407Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This injection vulnerability in NGINX Ingress Controller's configuration generator allows an authenticated attacker with write access to Ingress annotations to inject arbitrary NGINX configuration directives, potentially creating or deleting files, disrupting services, or making other configuration changes. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. There is no data plane exposure; this is a control plane issue only. Software versions that have reached End of Technical Support (EoTS) are not evaluated. The debrief provides an executive overview covering the affected product, vulnerability class, likely operational impact, and source-confidence limits.
- Vendor
- F5
- Product
- NGINX Ingress Controller
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
NGINX Ingress Controller administrators, Kubernetes cluster operators, security teams responsible for ingress controller configurations, and developers using NGINX Ingress Controller in their applications.
Technical summary
The NGINX Ingress Controller's configuration generator does not properly sanitize user-controllable fields from Ingress annotations. An authenticated attacker with write access to these annotations can craft malicious values that inject arbitrary NGINX configuration directives. This could lead to file creation or deletion, service disruption, or other configuration changes. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity.
Defensive priority
Authenticated attackers with write access to NGINX Ingress Controller Ingress annotations may inject arbitrary NGINX configuration directives, potentially creating or deleting files, or disabling services. This control plane issue requires immediate attention.
Recommended defensive actions
- Review and sanitize user-controllable fields in Ingress annotations.
- Restrict write access to NGINX Ingress Controller Ingress annotations.
- Monitor for suspicious changes to NGINX configuration.
- Verify NGINX Ingress Controller configurations against known good states.
- Implement compensating controls to detect and prevent configuration changes.
Evidence notes
The CVE-2026-77180 record indicates an injection vulnerability in NGINX Ingress Controller's configuration generator. An authenticated attacker with permission to create or modify Ingress annotations may craft values that inject arbitrary NGINX configuration directives. Impact includes potential file creation or deletion, service disruption, and configuration changes. No data plane exposure is noted; this is a control plane issue only. Software versions that have reached End of Technical Support (EoTS) are not evaluated.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77180 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77180
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77180 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77180
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://my.f5.com/manage/s/article/K000162601
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.