CVE-2026-107804: CWE-346: Origin Validation Error in 0xJacky nginx-ui
Description
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
CVSS v3.1
Score 5.3medium
Affected software
0xJacky
nginx-ui
pkg:github/0xjacky/nginx-uiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in nginx-ui versions >=2.2.0 and <2.6.0 arises because the bundled reverse proxy fails to preserve the external client IP identity, attributing requests to the loopback address. This misattribution allows management requests with valid credentials to bypass IP allowlist restrictions that exempt the loopback address. Additionally, failed login attempts from different external clients are all attributed to the same loopback address, enabling an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without affecting existing sessions. The flaw is classified as CWE-346 (Origin Validation Error) and has a CVSS 3.1 base score of 5.3 (medium severity). The issue is resolved in version 2.6.0.
Potential Impact
An attacker can exploit this vulnerability to bypass IP allowlist restrictions for management requests if valid credentials are provided, due to the proxy attributing requests to the loopback address. Furthermore, unauthenticated attackers can cause denial-of-service conditions by triggering shared temporary login bans across multiple clients without invalidating active sessions. There is no direct confidentiality or integrity impact reported. No known exploits are in the wild.
Mitigation Recommendations
Upgrade nginx-ui to version 2.6.0 or later, where this issue is fixed. Until then, be aware that the bundled reverse proxy does not preserve client IP identity, which may allow bypass of IP allowlist protections and enable denial-of-service via shared login bans. No other vendor advisories or patches are provided; therefore, patching to 2.6.0 is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-08T21:23:59.820Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac9026b2cdf04f656621286
Added to database: 10/09/2026, 15:04:11 UTC
Last enriched: 10/09/2026, 15:18:47 UTC
Last updated: 10/09/2026, 15:49:08 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.