MIRAGE
Threat IntelligenceCVEs › CVE-2026-42221

CVE-2026-42221 — exposed on the internet

CVE-2026-42221: CWE-306: Missing Authentication for Critical Function in 0xJacky nginx-ui

Internet exposure observed by OffSeq scans · last 30 days

2
Exposed hosts
8.1
CVSS
1.2%
EPSS

Found on 2 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-42221

CVE-2026-42221 is a high-severity vulnerability in 0xJacky's nginx-ui versions 2.0.0 up to but not including 2.3.8. It allows an unauthenticated remote attacker to claim the initial administrator account during the first-run setup by accessing the public /api/install endpoint without authentication. This leads to permanent takeover of the initial instance by setting the admin email, username, and password. The vulnerability arises because the installation endpoint lacks authentication, and encryption only protects data in transit, not the authorization of the installer. This issue has been fixed in version 2.3.

Vendor: 0xJackyCWE-306

OffSeq internet scanning found CVE-2026-42221 on 2 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

portainer

Open the live CVE-2026-42221 view →

References