A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component…
Medium CVSS 5.3
Summary
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/NginxProxyManager/nginx-proxy-manager/
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5594
- https://vuldb.com/cve/CVE-2026-93964
- https://vuldb.com/submit/944336
- https://vuldb.com/vuln/407923
- https://vuldb.com/vuln/407923/cti
Timeline
- nvd_ingest NVD