CVE-2026-107813 - Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
CVE ID :CVE-2026-107813 Published : Oct. 9, 2026, 4:17 p.m. | 1 hour, 12 minutes ago Description :Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart...