Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nginxproxymanager nginx-proxy-manager
|
|
| Vendors & Products |
Nginxproxymanager nginx-proxy-manager
|
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts. | |
| Title | Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config | |
| First Time appeared |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:21:41.746Z
Reserved: 2026-09-28T22:08:55.919Z
Link: CVE-2026-102335
No data.
Status : Received
Published: 2026-09-28T23:17:02.007
Modified: 2026-09-28T23:17:02.007
Link: CVE-2026-102335
No data.
OpenCVE Enrichment
Updated: 2026-09-29T02:45:06Z
Weaknesses