Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment environment data. A party that obtains the secret can bypass normal password, JWT, session, and second-factor checks and obtain persistent administrative API access, including access to configuration and secret material. This issue is fixed in version 2.5.0. | |
| Title | Nginx UI: Node Secret Credential Exposure via URL Query Parameter | |
| Weaknesses | CWE-312 CWE-598 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T15:04:18.109Z
Reserved: 2026-10-08T21:23:59.820Z
Link: CVE-2026-107807
No data.
Status : Awaiting Analysis
Published: 2026-10-09T16:17:25.087
Modified: 2026-10-09T16:38:57.820
Link: CVE-2026-107807
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:30:09Z