CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102335

HIGHCVSS 7.1NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control rou

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102335 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102335

HIGHCVSS 7.1NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control rou

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]