github.com
https://github.com/0xJacky/nginx-ui CVE-2026-42222
HIGH
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
Record summary
CVE-2026-42222 has a selected CVSS score of 8.1 (high).
Description
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
nginx-uiBrowse 0xJacky / nginx-ui | CVE List | = 2.3.5 | affected |
github.com/0xJacky/nginx-uiBrowse Go / github.com/0xJacky/nginx-ui | GitHub Advisory | 2.3.5 | affected |
References
3github.comConfirmation
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-mxqh-q9h6-v8pq nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-42222