CVE-2026-42220

MEDIUM CVSS 3.1: 6.5 EPSS 0.30%
Updated Jun 17, 2026
Nginxui
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 2.3.8
Fixed In 2.3.8
Type CWE-863 (Incorrect Authorization), CWE-200 (Information Exposure)
Vendor Nginxui
Public PoC No

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret query parameter), causing the request to be treated as authenticated via the trusted-node path and associated with the init user.

This issue has been patched in version 2.3.8.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Nginxui Nginx_Ui
cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*
2.3.8