PT-2026-36920 · Nginx-Ui · Nginx-Ui

Lilmingwa13

·

Published

2026-04-21

·

Updated

2026-05-06

·

CVE-2026-42220

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.8
Description An authenticated user can access the 'GET /api/settings' endpoint to retrieve sensitive configuration values, such as node.secret. This secret is accepted by the AuthRequired() function via the 'X-Node-Secret' header or the node secret query parameter, allowing requests to be treated as authenticated through the trusted-node path and associated with the init user.
Recommendations Update to version 2.3.8.

Exploit

Fix

Information Disclosure

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-06342
CVE-2026-42220
GHSA-7JRR-XW9C-MJ39

Affected Products

Nginx-Ui