PatchSiren

0xJacky CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107813

CVE-2026-107813 debrief based on Nginx UI source corpus. The vulnerability is an incomplete fix for CVE-2026-84315 in Nginx UI, affecting versions 2.0.0 to 2.4.0. The api/cluster router was not wrapped in RequireSecureSession, allowing authenticated OTP-enabled users with stolen or persisted JWTs to perform sensitive mutations without a fresh second-factor step-up. This issue allows node CRUD, read or rep [truncated]

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107812

CVE-2026-107812 Nginx UI Self-Upgrade Unsigned Binary Verification Bypass. Nginx UI, a web user interface for the Nginx web server, contains a self-upgrade mechanism that validates downloaded binaries only with a same-origin digest obtained from the same upgrade mirror. This allows for potential Remote Code Execution (RCE) via a compromised mirror or Man-In-The-Middle (MITM) attack. An operator-triggered [truncated]

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107811

CVE-2026-107811 is a high-severity vulnerability in 0xJacky's nginx-ui, affecting versions from 2.0.0 to 2.5.0. The issue allows ordinary authenticated users to access /api/nodes and /api/nodes/:id, leaking cluster node tokens. These tokens can be used to impersonate a trusted node, bypassing cross-node authentication. This could expose sensitive management operations such as configuration synchronization [truncated]

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107810

CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to inject configuration or cause denial of service through crafted backups. Affected versions (2.0.0-2.4.0) require patching or mitigation to prevent exploitation. The vulnerability is fixed in version 2.5.0. Nginx UI administrators, security teams, and users with access to backup and restore functionality should [truncated]

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107809

CVE-2026-107809 debrief: Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs. This issue allows a remote attacker to induce a logged-in administrator's browser to submit authenticated cross-site state-changing requests. The attack requires an administrator account without OTP/Passkey or a target endpoint that does not require secure-session proof.

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107808

CVE-2026-107808 Nginx UI Authentication Bypass: A high-severity vulnerability exists in Nginx UI, a web user interface for the Nginx web server, from version 2.0.0 to 2.5.0. The issue allows for authentication bypass due to not enforcing a passkey-only second factor when password login is used. This could enable an attacker who obtains the password to take over the account and reach administrative functio [truncated]

HIGH 0xJacky CVE published 2026-10-09

CVE-2026-107807

CVE-2026-107807 Nginx UI Node Secret Credential Exposure via URL Query Parameter. The vulnerability exists in Nginx UI from version 2.0.0 to 2.5.0, where the Node.Secret master credential is accepted through the node_secret query parameter in HTTP and WebSocket authentication paths. This allows the credential to appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and d [truncated]