Executive brief
Nginx Proxy Manager, a tool used to manage web traffic and security certificates, contains a flaw that allows authorized users to download sensitive security keys. While these users may have permission to view certificates, they should not be able to access the private keys used to encrypt traffic. An attacker with basic account access could use these keys to impersonate the website or intercept private communications, requiring the organization to revoke and replace the affected security certificates.
Technical details
An incorrect access control vulnerability exists in the certificate download functionality of Nginx Proxy Manager v2.14.0. The backend handler for the 'GET /api/nginx/certificates/:certificate_id/download' route, located in 'backend/internal/certificate.js', packages the entire contents of the live certificate directory into a ZIP archive. This process fails to filter out sensitive files, resulting in the inclusion of 'privkey.pem' in the download. An authenticated attacker with 'certificates:get' permissions can exploit this to obtain private key material that should remain restricted. This allows for the potential decryption of intercepted traffic or impersonation of the affected TLS endpoints.
Affected products
- Nginx Proxy Manager Nginx Proxy Manager 2.14.0
Timeline
- 2026-06-13: other: Vulnerability details shared on GitHub Gist
- 2026-06-15: disclosed: CVE published to NVD dataset