CVE-2026-107804
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
| CWE | CWE-346 |
| Vendor | 0xjacky |
| Product | nginx-ui |
| Published | Oct 9, 2026 |
| Last Updated | Oct 9, 2026 |
Get instant alerts for 0xjacky nginx-ui
Be the first to know when new medium vulnerabilities affecting 0xjacky nginx-ui are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L