Unauthenticated Remote Code Execution via Backup Restore in nginx-ui
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-42238. PoCs published by fuchiuebusi-lab.
AI-analyzed exploit summary This repository provides a detailed technical analysis and learning plan for CVE-2026-42221 (authentication bypass) and CVE-2026-42238 (unauthenticated RCE) in nginx-ui v2.3.7. It includes Docker setup files for a vulnerable environment and explains the attack chain, focusing on the `TestConfigCmd` setting as the core of the RCE vulnerability.
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQLite database. Because the attacker controls the restored app.ini, they can inject an arbitrary OS command into the TestConfigCmd setting. After the application automatically restarts to apply the restored config, a single follow-up request triggers that command as the user running nginx-ui — typically root in Docker deployments. This issue has been patched in version 2.3.8.
Exploits (1)
This repository provides a detailed technical analysis and learning plan for CVE-2026-42221 (authentication bypass) and CVE-2026-42238 (unauthenticated RCE) in nginx-ui v2.3.7. It includes Docker setup files for a vulnerable environment and explains the attack chain, focusing on the `TestConfigCmd` setting as the core of the RCE vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H