Junglewise Threat Intelligence
CVE-2026-42220: GO-2026-5227 - Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and rest
CVE-2026-42220 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/0xJacky/Nginx-UI (Go). Vendors: Go.
Executive brief
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI
Affected products
- Go github.com/0xJacky/Nginx-UI