CVE-2026-66362 | F5 NGINX Gateway Fabric up to 2.6.7 NGINX Configuration Generator clientID/cookieName/clientSecret code injection

SecurityVulns

A vulnerability was found in F5 NGINX Gateway Fabric up to 2.6.7. It has been classified as problematic. This issue affects some unknown processing of the component NGINX Configuration Generator. Performing a manipulation of the argument clientID/cookieName/clientSecret results in code injection.

This vulnerability was named CVE-2026-66362. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More