Search
Find a vulnerability
Search criteria
8 vulnerabilities found for nginx-proxy-manager by NginxProxyManager
CVE-2026-102335 (GCVE-0-2026-102335)
Vulnerability from nvd – Published: 2026-09-28 22:21 – Updated: 2026-09-30 14:06
VLAI
EPSS
VEX
Title
Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
Summary
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:06 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | issue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | patchissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
0 , ≤ 2.16.0
(custom)
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-07-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:06:50.639764Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:06:58.595Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.16.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.16.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lazizbek Djurayev (Haad TC)"
}
],
"datePublic": "2026-07-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T22:21:41.746Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config"
}
],
"title": "Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102335",
"datePublished": "2026-09-28T22:21:41.746Z",
"dateReserved": "2026-09-28T22:08:55.919Z",
"dateUpdated": "2026-09-30T14:06:58.595Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102334 (GCVE-0-2026-102334)
Vulnerability from nvd – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47
VLAI
EPSS
VEX
Title
Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
Summary
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
Severity
7.4 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 19:47 UTC
CWE
- CWE-307 - Improper Restriction of Excessive Authentication Attempts
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | patchissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
0 , ≤ 2.16.0
(custom)
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-09-28 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102334",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T19:47:02.219168Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T19:47:25.772Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.16.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.16.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lazizbek Djurayev (Haad TC)"
}
],
"datePublic": "2026-09-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T22:21:41.072Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
}
],
"title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102334",
"datePublished": "2026-09-28T22:21:41.072Z",
"dateReserved": "2026-09-28T22:08:55.547Z",
"dateUpdated": "2026-09-29T19:47:25.772Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93964 (GCVE-0-2026-93964)
Vulnerability from nvd – Published: 2026-09-20 05:30 – Updated: 2026-09-22 15:43
VLAI
EPSS
VEX
Title
NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
Summary
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:34 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407923 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/407923/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93964 | third-party-advisory |
| https://vuldb.com/submit/944336 | third-party-advisory |
| https://github.com/NginxProxyManager/nginx-proxy-… | exploitissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
2.0
Affected: 2.1 Affected: 2.1.0 Affected: 2.1.1 Affected: 2.1.2 Affected: 2.2 Affected: 2.2.0 Affected: 2.2.1 Affected: 2.2.2 Affected: 2.2.3 Affected: 2.2.4 Affected: 2.3 Affected: 2.3.0 Affected: 2.3.1 Affected: 2.4 Affected: 2.4.0 Affected: 2.5 Affected: 2.5.0 Affected: 2.6 Affected: 2.6.0 Affected: 2.6.1 Affected: 2.6.2 Affected: 2.7 Affected: 2.7.0 Affected: 2.7.1 Affected: 2.7.2 Affected: 2.7.3 Affected: 2.8 Affected: 2.8.0 Affected: 2.8.1 Affected: 2.9 Affected: 2.9.0 Affected: 2.9.1 Affected: 2.9.2 Affected: 2.9.3 Affected: 2.9.4 Affected: 2.9.5 Affected: 2.9.6 Affected: 2.9.7 Affected: 2.9.8 Affected: 2.9.9 Affected: 2.9.10 Affected: 2.9.11 Affected: 2.9.12 Affected: 2.9.13 Affected: 2.9.14 Affected: 2.9.15 Affected: 2.9.16 Affected: 2.9.17 Affected: 2.9.18 Affected: 2.9.19 Affected: 2.9.20 Affected: 2.9.21 Affected: 2.9.22 Affected: 2.10 Affected: 2.10.0 Affected: 2.10.1 Affected: 2.10.2 Affected: 2.10.3 Affected: 2.10.4 Affected: 2.11 Affected: 2.12 Affected: 2.13 Affected: 2.14.0 Affected: 2.15.0 Affected: 2.15.1 cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93964",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:34:02.996167Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:43:42.768Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*"
],
"modules": [
"Validate Route"
],
"product": "nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"status": "affected",
"version": "2.0"
},
{
"status": "affected",
"version": "2.1"
},
{
"status": "affected",
"version": "2.1.0"
},
{
"status": "affected",
"version": "2.1.1"
},
{
"status": "affected",
"version": "2.1.2"
},
{
"status": "affected",
"version": "2.2"
},
{
"status": "affected",
"version": "2.2.0"
},
{
"status": "affected",
"version": "2.2.1"
},
{
"status": "affected",
"version": "2.2.2"
},
{
"status": "affected",
"version": "2.2.3"
},
{
"status": "affected",
"version": "2.2.4"
},
{
"status": "affected",
"version": "2.3"
},
{
"status": "affected",
"version": "2.3.0"
},
{
"status": "affected",
"version": "2.3.1"
},
{
"status": "affected",
"version": "2.4"
},
{
"status": "affected",
"version": "2.4.0"
},
{
"status": "affected",
"version": "2.5"
},
{
"status": "affected",
"version": "2.5.0"
},
{
"status": "affected",
"version": "2.6"
},
{
"status": "affected",
"version": "2.6.0"
},
{
"status": "affected",
"version": "2.6.1"
},
{
"status": "affected",
"version": "2.6.2"
},
{
"status": "affected",
"version": "2.7"
},
{
"status": "affected",
"version": "2.7.0"
},
{
"status": "affected",
"version": "2.7.1"
},
{
"status": "affected",
"version": "2.7.2"
},
{
"status": "affected",
"version": "2.7.3"
},
{
"status": "affected",
"version": "2.8"
},
{
"status": "affected",
"version": "2.8.0"
},
{
"status": "affected",
"version": "2.8.1"
},
{
"status": "affected",
"version": "2.9"
},
{
"status": "affected",
"version": "2.9.0"
},
{
"status": "affected",
"version": "2.9.1"
},
{
"status": "affected",
"version": "2.9.2"
},
{
"status": "affected",
"version": "2.9.3"
},
{
"status": "affected",
"version": "2.9.4"
},
{
"status": "affected",
"version": "2.9.5"
},
{
"status": "affected",
"version": "2.9.6"
},
{
"status": "affected",
"version": "2.9.7"
},
{
"status": "affected",
"version": "2.9.8"
},
{
"status": "affected",
"version": "2.9.9"
},
{
"status": "affected",
"version": "2.9.10"
},
{
"status": "affected",
"version": "2.9.11"
},
{
"status": "affected",
"version": "2.9.12"
},
{
"status": "affected",
"version": "2.9.13"
},
{
"status": "affected",
"version": "2.9.14"
},
{
"status": "affected",
"version": "2.9.15"
},
{
"status": "affected",
"version": "2.9.16"
},
{
"status": "affected",
"version": "2.9.17"
},
{
"status": "affected",
"version": "2.9.18"
},
{
"status": "affected",
"version": "2.9.19"
},
{
"status": "affected",
"version": "2.9.20"
},
{
"status": "affected",
"version": "2.9.21"
},
{
"status": "affected",
"version": "2.9.22"
},
{
"status": "affected",
"version": "2.10"
},
{
"status": "affected",
"version": "2.10.0"
},
{
"status": "affected",
"version": "2.10.1"
},
{
"status": "affected",
"version": "2.10.2"
},
{
"status": "affected",
"version": "2.10.3"
},
{
"status": "affected",
"version": "2.10.4"
},
{
"status": "affected",
"version": "2.11"
},
{
"status": "affected",
"version": "2.12"
},
{
"status": "affected",
"version": "2.13"
},
{
"status": "affected",
"version": "2.14.0"
},
{
"status": "affected",
"version": "2.15.0"
},
{
"status": "affected",
"version": "2.15.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "geochen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T05:30:17.064Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407923 | NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/407923"
},
{
"name": "VDB-407923 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407923/cti"
},
{
"name": "CVE-2026-93964 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93964"
},
{
"name": "Submit #944336 | NginxProxyManager nginx-proxy-manager commit c354238 (v2.14.0) Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/944336"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5594"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-19T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-19T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-19T12:19:31.000Z",
"value": "VulDB entry last update"
}
],
"title": "NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93964",
"datePublished": "2026-09-20T05:30:17.064Z",
"dateReserved": "2026-09-19T10:14:26.749Z",
"dateUpdated": "2026-09-22T15:43:42.768Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-40519 (GCVE-0-2026-40519)
Vulnerability from nvd – Published: 2026-06-08 19:28 – Updated: 2026-07-14 20:00 X_Open Source
VLAI
EPSS
VEX
Title
Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
Summary
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-09 14:33 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | issue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | patch |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
2.9.14 , ≤ 2.15.1
(semver)
Unaffected: a5db5ed156355e3088e7d1ceb0533d4bae922def (git) cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-04-19 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-40519",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-09T14:33:34.717862Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-09T14:35:09.015Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.15.1",
"status": "affected",
"version": "2.9.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "a5db5ed156355e3088e7d1ceb0533d4bae922def",
"versionType": "git"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.15.1",
"versionStartIncluding": "2.9.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yassine Damiri"
}
],
"datePublic": "2026-04-19T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T20:00:32.823Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5498"
},
{
"tags": [
"patch"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-authenticated-rce-via-setupcertbotplugins"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-40519",
"datePublished": "2026-06-08T19:28:51.872Z",
"dateReserved": "2026-04-13T20:29:02.809Z",
"dateUpdated": "2026-07-14T20:00:32.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102335 (GCVE-0-2026-102335)
Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-30 14:06
VLAI
EPSS
VEX
Title
Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
Summary
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:06 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | issue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | patchissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
0 , ≤ 2.16.0
(custom)
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-07-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:06:50.639764Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:06:58.595Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.16.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.16.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lazizbek Djurayev (Haad TC)"
}
],
"datePublic": "2026-07-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T22:21:41.746Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config"
}
],
"title": "Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102335",
"datePublished": "2026-09-28T22:21:41.746Z",
"dateReserved": "2026-09-28T22:08:55.919Z",
"dateUpdated": "2026-09-30T14:06:58.595Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102334 (GCVE-0-2026-102334)
Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47
VLAI
EPSS
VEX
Title
Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
Summary
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
Severity
7.4 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 19:47 UTC
CWE
- CWE-307 - Improper Restriction of Excessive Authentication Attempts
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | patchissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | technical-description |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
0 , ≤ 2.16.0
(custom)
cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-09-28 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102334",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T19:47:02.219168Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T19:47:25.772Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.16.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.16.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lazizbek Djurayev (Haad TC)"
}
],
"datePublic": "2026-09-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T22:21:41.072Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
},
{
"name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
}
],
"title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-102334",
"datePublished": "2026-09-28T22:21:41.072Z",
"dateReserved": "2026-09-28T22:08:55.547Z",
"dateUpdated": "2026-09-29T19:47:25.772Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93964 (GCVE-0-2026-93964)
Vulnerability from cvelistv5 – Published: 2026-09-20 05:30 – Updated: 2026-09-22 15:43
VLAI
EPSS
VEX
Title
NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
Summary
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:34 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407923 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/407923/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93964 | third-party-advisory |
| https://vuldb.com/submit/944336 | third-party-advisory |
| https://github.com/NginxProxyManager/nginx-proxy-… | exploitissue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
2.0
Affected: 2.1 Affected: 2.1.0 Affected: 2.1.1 Affected: 2.1.2 Affected: 2.2 Affected: 2.2.0 Affected: 2.2.1 Affected: 2.2.2 Affected: 2.2.3 Affected: 2.2.4 Affected: 2.3 Affected: 2.3.0 Affected: 2.3.1 Affected: 2.4 Affected: 2.4.0 Affected: 2.5 Affected: 2.5.0 Affected: 2.6 Affected: 2.6.0 Affected: 2.6.1 Affected: 2.6.2 Affected: 2.7 Affected: 2.7.0 Affected: 2.7.1 Affected: 2.7.2 Affected: 2.7.3 Affected: 2.8 Affected: 2.8.0 Affected: 2.8.1 Affected: 2.9 Affected: 2.9.0 Affected: 2.9.1 Affected: 2.9.2 Affected: 2.9.3 Affected: 2.9.4 Affected: 2.9.5 Affected: 2.9.6 Affected: 2.9.7 Affected: 2.9.8 Affected: 2.9.9 Affected: 2.9.10 Affected: 2.9.11 Affected: 2.9.12 Affected: 2.9.13 Affected: 2.9.14 Affected: 2.9.15 Affected: 2.9.16 Affected: 2.9.17 Affected: 2.9.18 Affected: 2.9.19 Affected: 2.9.20 Affected: 2.9.21 Affected: 2.9.22 Affected: 2.10 Affected: 2.10.0 Affected: 2.10.1 Affected: 2.10.2 Affected: 2.10.3 Affected: 2.10.4 Affected: 2.11 Affected: 2.12 Affected: 2.13 Affected: 2.14.0 Affected: 2.15.0 Affected: 2.15.1 cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93964",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:34:02.996167Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:43:42.768Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*"
],
"modules": [
"Validate Route"
],
"product": "nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"status": "affected",
"version": "2.0"
},
{
"status": "affected",
"version": "2.1"
},
{
"status": "affected",
"version": "2.1.0"
},
{
"status": "affected",
"version": "2.1.1"
},
{
"status": "affected",
"version": "2.1.2"
},
{
"status": "affected",
"version": "2.2"
},
{
"status": "affected",
"version": "2.2.0"
},
{
"status": "affected",
"version": "2.2.1"
},
{
"status": "affected",
"version": "2.2.2"
},
{
"status": "affected",
"version": "2.2.3"
},
{
"status": "affected",
"version": "2.2.4"
},
{
"status": "affected",
"version": "2.3"
},
{
"status": "affected",
"version": "2.3.0"
},
{
"status": "affected",
"version": "2.3.1"
},
{
"status": "affected",
"version": "2.4"
},
{
"status": "affected",
"version": "2.4.0"
},
{
"status": "affected",
"version": "2.5"
},
{
"status": "affected",
"version": "2.5.0"
},
{
"status": "affected",
"version": "2.6"
},
{
"status": "affected",
"version": "2.6.0"
},
{
"status": "affected",
"version": "2.6.1"
},
{
"status": "affected",
"version": "2.6.2"
},
{
"status": "affected",
"version": "2.7"
},
{
"status": "affected",
"version": "2.7.0"
},
{
"status": "affected",
"version": "2.7.1"
},
{
"status": "affected",
"version": "2.7.2"
},
{
"status": "affected",
"version": "2.7.3"
},
{
"status": "affected",
"version": "2.8"
},
{
"status": "affected",
"version": "2.8.0"
},
{
"status": "affected",
"version": "2.8.1"
},
{
"status": "affected",
"version": "2.9"
},
{
"status": "affected",
"version": "2.9.0"
},
{
"status": "affected",
"version": "2.9.1"
},
{
"status": "affected",
"version": "2.9.2"
},
{
"status": "affected",
"version": "2.9.3"
},
{
"status": "affected",
"version": "2.9.4"
},
{
"status": "affected",
"version": "2.9.5"
},
{
"status": "affected",
"version": "2.9.6"
},
{
"status": "affected",
"version": "2.9.7"
},
{
"status": "affected",
"version": "2.9.8"
},
{
"status": "affected",
"version": "2.9.9"
},
{
"status": "affected",
"version": "2.9.10"
},
{
"status": "affected",
"version": "2.9.11"
},
{
"status": "affected",
"version": "2.9.12"
},
{
"status": "affected",
"version": "2.9.13"
},
{
"status": "affected",
"version": "2.9.14"
},
{
"status": "affected",
"version": "2.9.15"
},
{
"status": "affected",
"version": "2.9.16"
},
{
"status": "affected",
"version": "2.9.17"
},
{
"status": "affected",
"version": "2.9.18"
},
{
"status": "affected",
"version": "2.9.19"
},
{
"status": "affected",
"version": "2.9.20"
},
{
"status": "affected",
"version": "2.9.21"
},
{
"status": "affected",
"version": "2.9.22"
},
{
"status": "affected",
"version": "2.10"
},
{
"status": "affected",
"version": "2.10.0"
},
{
"status": "affected",
"version": "2.10.1"
},
{
"status": "affected",
"version": "2.10.2"
},
{
"status": "affected",
"version": "2.10.3"
},
{
"status": "affected",
"version": "2.10.4"
},
{
"status": "affected",
"version": "2.11"
},
{
"status": "affected",
"version": "2.12"
},
{
"status": "affected",
"version": "2.13"
},
{
"status": "affected",
"version": "2.14.0"
},
{
"status": "affected",
"version": "2.15.0"
},
{
"status": "affected",
"version": "2.15.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "geochen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T05:30:17.064Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407923 | NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/407923"
},
{
"name": "VDB-407923 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407923/cti"
},
{
"name": "CVE-2026-93964 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93964"
},
{
"name": "Submit #944336 | NginxProxyManager nginx-proxy-manager commit c354238 (v2.14.0) Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/944336"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5594"
},
{
"tags": [
"product"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-19T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-19T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-19T12:19:31.000Z",
"value": "VulDB entry last update"
}
],
"title": "NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93964",
"datePublished": "2026-09-20T05:30:17.064Z",
"dateReserved": "2026-09-19T10:14:26.749Z",
"dateUpdated": "2026-09-22T15:43:42.768Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-40519 (GCVE-0-2026-40519)
Vulnerability from cvelistv5 – Published: 2026-06-08 19:28 – Updated: 2026-07-14 20:00 X_Open Source
VLAI
EPSS
VEX
Title
Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
Summary
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-09 14:33 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/NginxProxyManager/nginx-proxy-… | issue-tracking |
| https://github.com/NginxProxyManager/nginx-proxy-… | patch |
| https://www.vulncheck.com/advisories/nginx-proxy-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager |
Affected:
2.9.14 , ≤ 2.15.1
(semver)
Unaffected: a5db5ed156355e3088e7d1ceb0533d4bae922def (git) cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* |
Date Public
2026-04-19 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-40519",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-09T14:33:34.717862Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-09T14:35:09.015Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
"product": "nginx-proxy-manager",
"repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
"vendor": "NginxProxyManager",
"versions": [
{
"lessThanOrEqual": "2.15.1",
"status": "affected",
"version": "2.9.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "a5db5ed156355e3088e7d1ceb0533d4bae922def",
"versionType": "git"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.15.1",
"versionStartIncluding": "2.9.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yassine Damiri"
}
],
"datePublic": "2026-04-19T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T20:00:32.823Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5498"
},
{
"tags": [
"patch"
],
"url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-authenticated-rce-via-setupcertbotplugins"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-40519",
"datePublished": "2026-06-08T19:28:51.872Z",
"dateReserved": "2026-04-13T20:29:02.809Z",
"dateUpdated": "2026-07-14T20:00:32.823Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}