Description

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

INFO

Published Date :

2026-05-04T20:11:11.049Z

Last Modified :

2026-05-06T13:58:55.214Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-42222 vulnerability.

Vendors Products
0xjacky
  • Nginx-ui
Nginxui
  • Nginx Ui
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-42222.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact