Answer in brief
CVE-2026-107807 records a High severity (CVSS 8.8) vulnerability in Nginx UI: Node Secret Credential Exposure via URL Query Parameter. The current sources do not mark it as known exploited. The current feed maps 0xJacky/nginx-ui (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps 0xJacky/nginx-ui (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| 0xJacky/nginx-uigeneric | >=2.0.0 <2.5.0 | 2.5.0 |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment environment data. A party that obtains the secret can bypass normal password, JWT, session, and second-factor checks and obtain persistent administrative API access, including access to configuration and secret material. This issue is fixed in version 2.5.0.
Quoted source text, attributed separately from HOL analysis.