Junglewise Threat Intelligence

CVE-2026-93964: NginxProxyManager nginx-proxy-manager authentication bypass in certificate validation

CVE-2026-93964 · Severity: medium · CVSS 5.3 · Published 2026-09-20

Executive brief

Nginx Proxy Manager, a Docker-based reverse proxy and SSL management tool, contains an unauthenticated endpoint that accepts and processes SSL certificates without verifying the caller's identity. An attacker can remotely submit malicious certificate data to this endpoint, causing the application to perform OpenSSL processing on untrusted input, potentially leading to denial of service or application crashes.

Technical details

The internalCertificate.validate function in backend/internal/certificate.js fails to enforce authentication on a route that accepts and processes certificate data. An unauthenticated attacker can submit arbitrary certificate input over the network, triggering OpenSSL operations without validation. The endpoint echoes back the submitted certificate; while no stored data is leaked, the real risk is uncontrolled processing of attacker-supplied certificate data that could crash or degrade the application.

Affected products

  • NginxProxyManager nginx-proxy-manager up to 2.15.1

Timeline

  • 2026-09-20: disclosed
  • 2026-05-27: other: Security issue reported on GitHub #5594; maintainers have not yet responded

References