Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQLite database. Because the attacker controls the restored app.ini, they can inject an arbitrary OS command into the TestConfigCmd setting. After the application automatically restarts to apply the restored config, a single follow-up request triggers that command as the user running nginx-ui — typically root in Docker deployments. This issue has been patched in version 2.3.8.
During the first 10 minutes after application startup, the POST /api/restore endpoint requires no authentication. An attacker sends a crafted backup archive that overwrites the app.ini configuration file and the SQLite database. Because the attacker controls the restored app.ini file, they can inject arbitrary system commands into the TestConfigCmd setting. After the application automatically restarts to load the restored configuration, a single subsequent request triggers execution of the injected command in the context of the user running nginx-ui — typically root in Docker environments.
An attacker can gain full control of the system by executing arbitrary OS commands with the privileges of the nginx-ui process (most commonly root), enabling compromise of both the application itself and the host system, as well as potentially adjacent environments (high impact on confidentiality, integrity, and availability in terms of the system and its surroundings).
Nginx UI should be updated to version 2.3.8 or later. The patch is available in the official repository: https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8. Until the update is applied, it is recommended to restrict network access to the Nginx UI administrative interface at the firewall level, especially during the first 10 minutes after each service startup or restart.
Nginx UI in versions earlier than 2.3.8, particularly fresh installations running in Docker containers.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNginxui nginx Ui
APPNginxui< 2.3.8
Related vulnerabilities
Nginx UI: manipulacja zaszyfrowanymi kopiami zapasowymi i wstrzyknięcie konfiguracji
Nginx UI: nieuwierzytelniony dostęp do endpointu MCP umożliwia przejęcie serwera
Nginx UI: nieuwierzytelniony dostęp do backupu z ujawnieniem kluczy szyfrowania
Nginx-UI: path traversal w imporcie certyfikatów umożliwia RCE
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can per...