Update Nginx UI to 2.5.0 to Fix CVE-2026-107810 Symlink Flaw in Backup Restore Process
CVE-2026-107810 lets attackers inject malicious files into live Nginx configurations via a symlink vulnerability in the backup restore process.
Key points
- The flaw affects Nginx UI versions 2.0.0 through 2.4.x, rated High severity with a CVSS score of 8.1.
- Attackers can bypass restore flags to write arbitrary files to the live Nginx configuration directory.
- A fix is available in Nginx UI version 2.5.0, which addresses the symlink extraction issue.
Authenticated users with backup privileges in Nginx UI can exploit a symlink vulnerability to modify live server configurations. The issue, tracked as CVE-2026-107810, allows attackers to bypass intended security controls during the backup restoration process.
What happened
Nginx UI is a web-based interface for managing Nginx web servers. According to the National Vulnerability Database (NVD), the vulnerability exists in versions 2.0.0 up to, but not including, 2.5.0. The flaw resides in the `internal/backup/restore.go` file.
When a user initiates a backup restoration, the application extracts the archive contents before applying specific restore flags. The GitHub Security Advisory (GHSA-p8v3-89rh-jxc7) explains that the extractor permits symlinks pointing to the live Nginx configuration path. Even if the `restore_nginx` and `restore_nginx_ui` flags are set to false, the system processes the symlinked paths.
An attacker can craft a backup archive containing a symlink to the live configuration directory. When the system extracts subsequent regular files from the archive, it writes them through the symlink. This action modifies the live Nginx configuration tree despite the user opting out of restoring those specific components. The vulnerability enables persistent injection of configuration changes or denial-of-service conditions.
Why it matters
The flaw is rated High severity with a CVSS score of 8.1. It affects the integrity of the Nginx web server configuration. Organizations using Nginx UI for server management face risks if users with backup privileges are compromised.
The vulnerability allows attackers to bypass the application's trust boundary. This can lead to unauthorized changes in server behavior, potential data exfiltration, or service disruption. The issue is particularly dangerous because it exploits a routine administrative function—backup restoration—making it likely to be overlooked in standard security reviews.
What to watch
- Monitor for unusual changes in Nginx configuration files.
- Review access logs for unauthorized backup restoration attempts.
- Check for unexpected symlink creation in staging directories.
- Verify that all Nginx UI installations are updated to version 2.5.0 or later.
What to do and how to stay safe: Nginx UI
- Update Nginx UI to version 2.5.0 or later to apply the vendor-provided fix.
- Implement strict access controls for backup restoration privileges.
- Regularly audit Nginx configuration files for unauthorized modifications.
- Monitor system logs for signs of suspicious backup activity.
General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is CVE-2026-107810?
CVE-2026-107810 is a high-severity vulnerability in Nginx UI that allows authenticated users to modify live Nginx configurations via a symlink flaw in the backup restoration process.
Which versions of Nginx UI are affected?
Nginx UI versions 2.0.0 up to, but not including, 2.5.0 are affected by this vulnerability.
How can organizations mitigate this risk?
Organizations should update Nginx UI to version 2.5.0 or later, implement strict access controls for backup privileges, and regularly audit configuration files for unauthorized changes.




