CVE-2026-66362 | F5 NGINX Gateway Fabric up to 2.6.7 NGINX Configuration Generator clientID/cookieName/clientSecret code injection
A vulnerability was found in F5 NGINX Gateway Fabric up to 2.6.7. It has been classified as problematic. This issue affects some unknown processing of the component NGINX Configuration Generator. Performing a manipulation of the argument clientID/cookieName/clientSecret results in code injection.
This vulnerability was named CVE-2026-66362. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More