THREAT OPS › Threat News › [NVD] CVE-2026-90581 (MEDIUM 6.3) — A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The expl
[NVD] CVE-2026-90581 (MEDIUM 6.3) — A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The expl
CVE-2026-90581 CVSS: 6.3 MEDIUM Published: 2026-09-13T20:16:51.487
A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Indicators of compromise
- CVE-2026-90581cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90581