CRITICAL
9.1 CVE-2026-86542 Published 7 Sept 2026
Nginx Import Name Validation Bypass
Worried this affects one of your servers?
Nginx versions before 0.30.0 fail to validate import names in the import routes.
Unauthenticated attackers can exploit this to write files outside the intended directory.
They can use traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files.
Reference: CVE-2026-86542 on NVD
← Back to Security News