---
id: CVE-2026-90581
title: A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2
summary: >-
  A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue
  affects the function MainController.autoUpdate of the file
  /adminPage/main/autoUpdate. This manipulation of the argument url causes code
  injection. Remote explo…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
vendor: cym1102
product: nginxWebUI
affected:
  - nginxWebUI 4.4.0
  - nginxWebUI 4.4.1
  - nginxWebUI 4.4.2
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90581'
references:
  - url: 'https://github.com/cym1102/nginxWebUI/'
    label: cna@vuldb.com
  - url: 'https://github.com/cym1102/nginxWebUI/issues/213'
    label: cna@vuldb.com
  - url: 'https://github.com/cym1102/nginxWebUI/pull/215'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90581'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913328'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403166'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403166/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T15:23:29.107628Z'
ingestedAt: '2026-09-14T15:23:07.469Z'
epss: 0.00413
epssPercentile: 0.33054
---

## Overview

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
