Search

Find a vulnerability

Search criteria

    8 vulnerabilities found for nginx-proxy-manager by NginxProxyManager

    CVE-2026-102335 (GCVE-0-2026-102335)

    Vulnerability from nvd – Published: 2026-09-28 22:21 – Updated: 2026-09-30 14:06
    VLAI
    Title
    Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
    Summary
    Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:06 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 0 , ≤ 2.16.0 (custom)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102335",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:06:50.639764Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T14:06:58.595Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.16.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-07-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T22:21:41.746Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
            },
            {
              "name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config"
            }
          ],
          "title": "Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102335",
        "datePublished": "2026-09-28T22:21:41.746Z",
        "dateReserved": "2026-09-28T22:08:55.919Z",
        "dateUpdated": "2026-09-30T14:06:58.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102334 (GCVE-0-2026-102334)

    Vulnerability from nvd – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47
    VLAI
    Title
    Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
    Summary
    Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 19:47 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 0 , ≤ 2.16.0 (custom)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102334",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T19:47:02.219168Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T19:47:25.772Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.16.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T22:21:41.072Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
            },
            {
              "name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
            }
          ],
          "title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102334",
        "datePublished": "2026-09-28T22:21:41.072Z",
        "dateReserved": "2026-09-28T22:08:55.547Z",
        "dateUpdated": "2026-09-29T19:47:25.772Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93964 (GCVE-0-2026-93964)

    Vulnerability from nvd – Published: 2026-09-20 05:30 – Updated: 2026-09-22 15:43
    VLAI
    Title
    NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
    Summary
    A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:34 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 2.0
    Affected: 2.1
    Affected: 2.1.0
    Affected: 2.1.1
    Affected: 2.1.2
    Affected: 2.2
    Affected: 2.2.0
    Affected: 2.2.1
    Affected: 2.2.2
    Affected: 2.2.3
    Affected: 2.2.4
    Affected: 2.3
    Affected: 2.3.0
    Affected: 2.3.1
    Affected: 2.4
    Affected: 2.4.0
    Affected: 2.5
    Affected: 2.5.0
    Affected: 2.6
    Affected: 2.6.0
    Affected: 2.6.1
    Affected: 2.6.2
    Affected: 2.7
    Affected: 2.7.0
    Affected: 2.7.1
    Affected: 2.7.2
    Affected: 2.7.3
    Affected: 2.8
    Affected: 2.8.0
    Affected: 2.8.1
    Affected: 2.9
    Affected: 2.9.0
    Affected: 2.9.1
    Affected: 2.9.2
    Affected: 2.9.3
    Affected: 2.9.4
    Affected: 2.9.5
    Affected: 2.9.6
    Affected: 2.9.7
    Affected: 2.9.8
    Affected: 2.9.9
    Affected: 2.9.10
    Affected: 2.9.11
    Affected: 2.9.12
    Affected: 2.9.13
    Affected: 2.9.14
    Affected: 2.9.15
    Affected: 2.9.16
    Affected: 2.9.17
    Affected: 2.9.18
    Affected: 2.9.19
    Affected: 2.9.20
    Affected: 2.9.21
    Affected: 2.9.22
    Affected: 2.10
    Affected: 2.10.0
    Affected: 2.10.1
    Affected: 2.10.2
    Affected: 2.10.3
    Affected: 2.10.4
    Affected: 2.11
    Affected: 2.12
    Affected: 2.13
    Affected: 2.14.0
    Affected: 2.15.0
    Affected: 2.15.1
        cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93964",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:34:02.996167Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:43:42.768Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Validate Route"
              ],
              "product": "nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.1.0"
                },
                {
                  "status": "affected",
                  "version": "2.1.1"
                },
                {
                  "status": "affected",
                  "version": "2.1.2"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                },
                {
                  "status": "affected",
                  "version": "2.2.0"
                },
                {
                  "status": "affected",
                  "version": "2.2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2.2"
                },
                {
                  "status": "affected",
                  "version": "2.2.3"
                },
                {
                  "status": "affected",
                  "version": "2.2.4"
                },
                {
                  "status": "affected",
                  "version": "2.3"
                },
                {
                  "status": "affected",
                  "version": "2.3.0"
                },
                {
                  "status": "affected",
                  "version": "2.3.1"
                },
                {
                  "status": "affected",
                  "version": "2.4"
                },
                {
                  "status": "affected",
                  "version": "2.4.0"
                },
                {
                  "status": "affected",
                  "version": "2.5"
                },
                {
                  "status": "affected",
                  "version": "2.5.0"
                },
                {
                  "status": "affected",
                  "version": "2.6"
                },
                {
                  "status": "affected",
                  "version": "2.6.0"
                },
                {
                  "status": "affected",
                  "version": "2.6.1"
                },
                {
                  "status": "affected",
                  "version": "2.6.2"
                },
                {
                  "status": "affected",
                  "version": "2.7"
                },
                {
                  "status": "affected",
                  "version": "2.7.0"
                },
                {
                  "status": "affected",
                  "version": "2.7.1"
                },
                {
                  "status": "affected",
                  "version": "2.7.2"
                },
                {
                  "status": "affected",
                  "version": "2.7.3"
                },
                {
                  "status": "affected",
                  "version": "2.8"
                },
                {
                  "status": "affected",
                  "version": "2.8.0"
                },
                {
                  "status": "affected",
                  "version": "2.8.1"
                },
                {
                  "status": "affected",
                  "version": "2.9"
                },
                {
                  "status": "affected",
                  "version": "2.9.0"
                },
                {
                  "status": "affected",
                  "version": "2.9.1"
                },
                {
                  "status": "affected",
                  "version": "2.9.2"
                },
                {
                  "status": "affected",
                  "version": "2.9.3"
                },
                {
                  "status": "affected",
                  "version": "2.9.4"
                },
                {
                  "status": "affected",
                  "version": "2.9.5"
                },
                {
                  "status": "affected",
                  "version": "2.9.6"
                },
                {
                  "status": "affected",
                  "version": "2.9.7"
                },
                {
                  "status": "affected",
                  "version": "2.9.8"
                },
                {
                  "status": "affected",
                  "version": "2.9.9"
                },
                {
                  "status": "affected",
                  "version": "2.9.10"
                },
                {
                  "status": "affected",
                  "version": "2.9.11"
                },
                {
                  "status": "affected",
                  "version": "2.9.12"
                },
                {
                  "status": "affected",
                  "version": "2.9.13"
                },
                {
                  "status": "affected",
                  "version": "2.9.14"
                },
                {
                  "status": "affected",
                  "version": "2.9.15"
                },
                {
                  "status": "affected",
                  "version": "2.9.16"
                },
                {
                  "status": "affected",
                  "version": "2.9.17"
                },
                {
                  "status": "affected",
                  "version": "2.9.18"
                },
                {
                  "status": "affected",
                  "version": "2.9.19"
                },
                {
                  "status": "affected",
                  "version": "2.9.20"
                },
                {
                  "status": "affected",
                  "version": "2.9.21"
                },
                {
                  "status": "affected",
                  "version": "2.9.22"
                },
                {
                  "status": "affected",
                  "version": "2.10"
                },
                {
                  "status": "affected",
                  "version": "2.10.0"
                },
                {
                  "status": "affected",
                  "version": "2.10.1"
                },
                {
                  "status": "affected",
                  "version": "2.10.2"
                },
                {
                  "status": "affected",
                  "version": "2.10.3"
                },
                {
                  "status": "affected",
                  "version": "2.10.4"
                },
                {
                  "status": "affected",
                  "version": "2.11"
                },
                {
                  "status": "affected",
                  "version": "2.12"
                },
                {
                  "status": "affected",
                  "version": "2.13"
                },
                {
                  "status": "affected",
                  "version": "2.14.0"
                },
                {
                  "status": "affected",
                  "version": "2.15.0"
                },
                {
                  "status": "affected",
                  "version": "2.15.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "geochen (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T05:30:17.064Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407923 | NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407923"
            },
            {
              "name": "VDB-407923 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407923/cti"
            },
            {
              "name": "CVE-2026-93964 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-93964"
            },
            {
              "name": "Submit #944336 | NginxProxyManager nginx-proxy-manager commit c354238 (v2.14.0) Missing Authentication",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/944336"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5594"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T12:19:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-93964",
        "datePublished": "2026-09-20T05:30:17.064Z",
        "dateReserved": "2026-09-19T10:14:26.749Z",
        "dateUpdated": "2026-09-22T15:43:42.768Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-40519 (GCVE-0-2026-40519)

    Vulnerability from nvd – Published: 2026-06-08 19:28 – Updated: 2026-07-14 20:00 X_Open Source
    VLAI
    Title
    Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
    Summary
    Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-09 14:33 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 2.9.14 , ≤ 2.15.1 (semver)
    Unaffected: a5db5ed156355e3088e7d1ceb0533d4bae922def (git)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-04-19 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-40519",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-09T14:33:34.717862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-09T14:35:09.015Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.15.1",
                  "status": "affected",
                  "version": "2.9.14",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "a5db5ed156355e3088e7d1ceb0533d4bae922def",
                  "versionType": "git"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.15.1",
                      "versionStartIncluding": "2.9.14",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yassine Damiri"
            }
          ],
          "datePublic": "2026-04-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T20:00:32.823Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5498"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-authenticated-rce-via-setupcertbotplugins"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-40519",
        "datePublished": "2026-06-08T19:28:51.872Z",
        "dateReserved": "2026-04-13T20:29:02.809Z",
        "dateUpdated": "2026-07-14T20:00:32.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102335 (GCVE-0-2026-102335)

    Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-30 14:06
    VLAI
    Title
    Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
    Summary
    Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:06 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 0 , ≤ 2.16.0 (custom)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102335",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:06:50.639764Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T14:06:58.595Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.16.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-07-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T22:21:41.746Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
            },
            {
              "name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config"
            }
          ],
          "title": "Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102335",
        "datePublished": "2026-09-28T22:21:41.746Z",
        "dateReserved": "2026-09-28T22:08:55.919Z",
        "dateUpdated": "2026-09-30T14:06:58.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102334 (GCVE-0-2026-102334)

    Vulnerability from cvelistv5 – Published: 2026-09-28 22:21 – Updated: 2026-09-29 19:47
    VLAI
    Title
    Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
    Summary
    Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 19:47 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 0 , ≤ 2.16.0 (custom)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102334",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T19:47:02.219168Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T19:47:25.772Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.16.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-09-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T22:21:41.072Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager"
            },
            {
              "name": "VulnCheck Advisory: Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"
            }
          ],
          "title": "Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102334",
        "datePublished": "2026-09-28T22:21:41.072Z",
        "dateReserved": "2026-09-28T22:08:55.547Z",
        "dateUpdated": "2026-09-29T19:47:25.772Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93964 (GCVE-0-2026-93964)

    Vulnerability from cvelistv5 – Published: 2026-09-20 05:30 – Updated: 2026-09-22 15:43
    VLAI
    Title
    NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
    Summary
    A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:34 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 2.0
    Affected: 2.1
    Affected: 2.1.0
    Affected: 2.1.1
    Affected: 2.1.2
    Affected: 2.2
    Affected: 2.2.0
    Affected: 2.2.1
    Affected: 2.2.2
    Affected: 2.2.3
    Affected: 2.2.4
    Affected: 2.3
    Affected: 2.3.0
    Affected: 2.3.1
    Affected: 2.4
    Affected: 2.4.0
    Affected: 2.5
    Affected: 2.5.0
    Affected: 2.6
    Affected: 2.6.0
    Affected: 2.6.1
    Affected: 2.6.2
    Affected: 2.7
    Affected: 2.7.0
    Affected: 2.7.1
    Affected: 2.7.2
    Affected: 2.7.3
    Affected: 2.8
    Affected: 2.8.0
    Affected: 2.8.1
    Affected: 2.9
    Affected: 2.9.0
    Affected: 2.9.1
    Affected: 2.9.2
    Affected: 2.9.3
    Affected: 2.9.4
    Affected: 2.9.5
    Affected: 2.9.6
    Affected: 2.9.7
    Affected: 2.9.8
    Affected: 2.9.9
    Affected: 2.9.10
    Affected: 2.9.11
    Affected: 2.9.12
    Affected: 2.9.13
    Affected: 2.9.14
    Affected: 2.9.15
    Affected: 2.9.16
    Affected: 2.9.17
    Affected: 2.9.18
    Affected: 2.9.19
    Affected: 2.9.20
    Affected: 2.9.21
    Affected: 2.9.22
    Affected: 2.10
    Affected: 2.10.0
    Affected: 2.10.1
    Affected: 2.10.2
    Affected: 2.10.3
    Affected: 2.10.4
    Affected: 2.11
    Affected: 2.12
    Affected: 2.13
    Affected: 2.14.0
    Affected: 2.15.0
    Affected: 2.15.1
        cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93964",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:34:02.996167Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:43:42.768Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:nginxproxymanager:nginx-proxy-manager:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Validate Route"
              ],
              "product": "nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.0"
                },
                {
                  "status": "affected",
                  "version": "2.1"
                },
                {
                  "status": "affected",
                  "version": "2.1.0"
                },
                {
                  "status": "affected",
                  "version": "2.1.1"
                },
                {
                  "status": "affected",
                  "version": "2.1.2"
                },
                {
                  "status": "affected",
                  "version": "2.2"
                },
                {
                  "status": "affected",
                  "version": "2.2.0"
                },
                {
                  "status": "affected",
                  "version": "2.2.1"
                },
                {
                  "status": "affected",
                  "version": "2.2.2"
                },
                {
                  "status": "affected",
                  "version": "2.2.3"
                },
                {
                  "status": "affected",
                  "version": "2.2.4"
                },
                {
                  "status": "affected",
                  "version": "2.3"
                },
                {
                  "status": "affected",
                  "version": "2.3.0"
                },
                {
                  "status": "affected",
                  "version": "2.3.1"
                },
                {
                  "status": "affected",
                  "version": "2.4"
                },
                {
                  "status": "affected",
                  "version": "2.4.0"
                },
                {
                  "status": "affected",
                  "version": "2.5"
                },
                {
                  "status": "affected",
                  "version": "2.5.0"
                },
                {
                  "status": "affected",
                  "version": "2.6"
                },
                {
                  "status": "affected",
                  "version": "2.6.0"
                },
                {
                  "status": "affected",
                  "version": "2.6.1"
                },
                {
                  "status": "affected",
                  "version": "2.6.2"
                },
                {
                  "status": "affected",
                  "version": "2.7"
                },
                {
                  "status": "affected",
                  "version": "2.7.0"
                },
                {
                  "status": "affected",
                  "version": "2.7.1"
                },
                {
                  "status": "affected",
                  "version": "2.7.2"
                },
                {
                  "status": "affected",
                  "version": "2.7.3"
                },
                {
                  "status": "affected",
                  "version": "2.8"
                },
                {
                  "status": "affected",
                  "version": "2.8.0"
                },
                {
                  "status": "affected",
                  "version": "2.8.1"
                },
                {
                  "status": "affected",
                  "version": "2.9"
                },
                {
                  "status": "affected",
                  "version": "2.9.0"
                },
                {
                  "status": "affected",
                  "version": "2.9.1"
                },
                {
                  "status": "affected",
                  "version": "2.9.2"
                },
                {
                  "status": "affected",
                  "version": "2.9.3"
                },
                {
                  "status": "affected",
                  "version": "2.9.4"
                },
                {
                  "status": "affected",
                  "version": "2.9.5"
                },
                {
                  "status": "affected",
                  "version": "2.9.6"
                },
                {
                  "status": "affected",
                  "version": "2.9.7"
                },
                {
                  "status": "affected",
                  "version": "2.9.8"
                },
                {
                  "status": "affected",
                  "version": "2.9.9"
                },
                {
                  "status": "affected",
                  "version": "2.9.10"
                },
                {
                  "status": "affected",
                  "version": "2.9.11"
                },
                {
                  "status": "affected",
                  "version": "2.9.12"
                },
                {
                  "status": "affected",
                  "version": "2.9.13"
                },
                {
                  "status": "affected",
                  "version": "2.9.14"
                },
                {
                  "status": "affected",
                  "version": "2.9.15"
                },
                {
                  "status": "affected",
                  "version": "2.9.16"
                },
                {
                  "status": "affected",
                  "version": "2.9.17"
                },
                {
                  "status": "affected",
                  "version": "2.9.18"
                },
                {
                  "status": "affected",
                  "version": "2.9.19"
                },
                {
                  "status": "affected",
                  "version": "2.9.20"
                },
                {
                  "status": "affected",
                  "version": "2.9.21"
                },
                {
                  "status": "affected",
                  "version": "2.9.22"
                },
                {
                  "status": "affected",
                  "version": "2.10"
                },
                {
                  "status": "affected",
                  "version": "2.10.0"
                },
                {
                  "status": "affected",
                  "version": "2.10.1"
                },
                {
                  "status": "affected",
                  "version": "2.10.2"
                },
                {
                  "status": "affected",
                  "version": "2.10.3"
                },
                {
                  "status": "affected",
                  "version": "2.10.4"
                },
                {
                  "status": "affected",
                  "version": "2.11"
                },
                {
                  "status": "affected",
                  "version": "2.12"
                },
                {
                  "status": "affected",
                  "version": "2.13"
                },
                {
                  "status": "affected",
                  "version": "2.14.0"
                },
                {
                  "status": "affected",
                  "version": "2.15.0"
                },
                {
                  "status": "affected",
                  "version": "2.15.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "geochen (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T05:30:17.064Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407923 | NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407923"
            },
            {
              "name": "VDB-407923 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407923/cti"
            },
            {
              "name": "CVE-2026-93964 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-93964"
            },
            {
              "name": "Submit #944336 | NginxProxyManager nginx-proxy-manager commit c354238 (v2.14.0) Missing Authentication",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/944336"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5594"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T12:19:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-93964",
        "datePublished": "2026-09-20T05:30:17.064Z",
        "dateReserved": "2026-09-19T10:14:26.749Z",
        "dateUpdated": "2026-09-22T15:43:42.768Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-40519 (GCVE-0-2026-40519)

    Vulnerability from cvelistv5 – Published: 2026-06-08 19:28 – Updated: 2026-07-14 20:00 X_Open Source
    VLAI
    Title
    Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
    Summary
    Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-09 14:33 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    NginxProxyManager nginx-proxy-manager Affected: 2.9.14 , ≤ 2.15.1 (semver)
    Unaffected: a5db5ed156355e3088e7d1ceb0533d4bae922def (git)
        cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-04-19 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-40519",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-09T14:33:34.717862Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-09T14:35:09.015Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "packageURL": "pkg:github/NginxProxyManager/nginx-proxy-manager",
              "product": "nginx-proxy-manager",
              "repo": "https://github.com/NginxProxyManager/nginx-proxy-manager",
              "vendor": "NginxProxyManager",
              "versions": [
                {
                  "lessThanOrEqual": "2.15.1",
                  "status": "affected",
                  "version": "2.9.14",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "a5db5ed156355e3088e7d1ceb0533d4bae922def",
                  "versionType": "git"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.15.1",
                      "versionStartIncluding": "2.9.14",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yassine Damiri"
            }
          ],
          "datePublic": "2026-04-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T20:00:32.823Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5498"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nginx-proxy-manager-authenticated-rce-via-setupcertbotplugins"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-40519",
        "datePublished": "2026-06-08T19:28:51.872Z",
        "dateReserved": "2026-04-13T20:29:02.809Z",
        "dateUpdated": "2026-07-14T20:00:32.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }