CVE-2026-93964 | NginxProxyManager nginx-proxy-manager up to 2.15.1 Validate Route certificate.js internalCertificate.validate missing authentication (Issue 5594)

SecurityVulns

A vulnerability was found in NginxProxyManager nginx-proxy-manager up to 2.15.1 and classified as problematic. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication.

This vulnerability is reported as CVE-2026-93964. The attack can be launched remotely. Moreover, an exploit is present.

Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More