CRITICAL 9.1 CVE-2026-86542 Published 7 Sept 2026

Nginx Import Name Validation Bypass

Worried this affects one of your servers?

Nginx versions before 0.30.0 fail to validate import names in the import routes.

Unauthenticated attackers can exploit this to write files outside the intended directory.

They can use traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files.

Reference: CVE-2026-86542 on NVD

← Back to Security News