<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:09:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06341</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06341</link>
      <description>bdu:2026-06341</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06341</guid>
    </item>
    <item>
      <title>EUVD-2026-308702</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308702</link>
      <description>EUVD-2026-308702</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308702</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42222</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42222</link>
      <description>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42222</guid>
    </item>
    <item>
      <title>GHSA-mxqh-q9h6-v8pq — Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mxqh-q9h6-v8pq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/nginx-ui&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An unauthenticated bootstrap takeover exists in `nginx-ui` during the initial installation window exposed by `POST /api/install`.&lt;/p&gt;
&lt;p&gt;When the instance is still uninitialized, `POST /api/install` is reachable without authentication and accepts attacker-controlled bootstrap data. The handler sets the application&amp;#39;s JWT secret, the node secret, the certificate email, and the initial administrator username and password. This allows an attacker who can reach a fresh instance during the initial 10-minute setup window to claim the installation before the legitimate operator.&lt;/p&gt;
&lt;p&gt;This is not a general post-install takeover. The exposure condition is narrower: the target must still be in its first-run state and still be within the initial setup window. In practice, this makes the issue most relevant during initial deployment, rebuilds, ephemeral test environments, LAN-accessible fresh installs, or temporarily exposed setup workflows.&lt;/p&gt;
&lt;p&gt;The primary attack path is direct network access to a reachable fresh instance.[^cors]&lt;/p&gt;
&lt;p&gt;This was reproduced over HTTP against live local instances started from `nginx-ui` `v2.3.5` using Docker image `uozi/nginx-ui@sha256:d73343e3009c9b558129a2be0cacd6c2c57ed8006a5871873b874b812e612e5a` (`org.opencontainers.image.version=2.3.5`, revision `1a9cd29a308278173aa0f16234cb78061dd2bd42`).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This issue allows full unauthenticated takeover of a fresh `nginx-ui` instance during the initial installation window.&lt;/p&gt;
&lt;p&gt;The practical exposure window is limi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/nginx-ui&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An unauthenticated bootstrap takeover exists in `nginx-ui` during the initial installation window exposed by `POST /api/install`.&lt;/p&gt;
&lt;p&gt;When the instance is still uninitialized, `POST /api/install` is reachable without authentication and accepts attacker-controlled bootstrap data. The handler sets the application&amp;#39;s JWT secret, the node secret, the certificate email, and the initial administrator username and password. This allows an attacker who can reach a fresh instance during the initial 10-minute setup window to claim the installation before the legitimate operator.&lt;/p&gt;
&lt;p&gt;This is not a general post-install takeover. The exposure condition is narrower: the target must still be in its first-run state and still be within the initial setup window. In practice, this makes the issue most relevant during initial deployment, rebuilds, ephemeral test environments, LAN-accessible fresh installs, or temporarily exposed setup workflows.&lt;/p&gt;
&lt;p&gt;The primary attack path is direct network access to a reachable fresh instance.[^cors]&lt;/p&gt;
&lt;p&gt;This was reproduced over HTTP against live local instances started from `nginx-ui` `v2.3.5` using Docker image `uozi/nginx-ui@sha256:d73343e3009c9b558129a2be0cacd6c2c57ed8006a5871873b874b812e612e5a` (`org.opencontainers.image.version=2.3.5`, revision `1a9cd29a308278173aa0f16234cb78061dd2bd42`).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This issue allows full unauthenticated takeover of a fresh `nginx-ui` instance during the initial installation window.&lt;/p&gt;
&lt;p&gt;The practical exposure window is limi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mxqh-q9h6-v8pq</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1276 — nginx-ui: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, sich Administratorrechte zu verschaffen und die vollständige Kontrolle über das System zu erlangen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, sich Administratorrechte zu verschaffen und die vollständige Kontrolle über das System zu erlangen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276</guid>
    </item>
  </channel>
</rss>
