← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 13, 2026 · 20:16via CVEFeed

CVE-2026-90581 - cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection

Brief

CVE ID : CVE-2026-90581

Published : Sept. 13, 2026, 8:16 p. m.

  • 36 minutes ago

Description : A vulnerability was determined in cym1102 nginxWebUI up to 4.

  • 2. This issue affects the function MainController. autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

Severity: 6.5

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→