CVE-2026-90581 | cym1102 nginxWebUI up to 4.4.2 autoUpdate MainController.autoUpdate url code injection (Issue 213)
A vulnerability was found in cym1102 nginxWebUI up to 4.4.2. It has been rated as critical. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection.
This vulnerability is registered as CVE-2026-90581. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More