CVE-2026-66362
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.35%
- CWE
- CWE-76
- Published
- 2026-09-02
- Last modified
- 2026-09-03
Affected products
- F5 NGINX Gateway Fabric
Weakness type
Related vulnerabilities
- CVE-2026-77180 — NGINX Ingress Controller vulnerability
- CVE-2026-54722 — dssrf: there a critical security bug with remove_at_symbol_in_string
- CVE-2026-55723 — NGINX Ingress Controller vulnerability
- CVE-2026-11311 — NGINX Gateway Fabric vulnerability
- CVE-2024-4897 — Remote Code Execution in parisneo/lollms-webui
- CVE-2024-34359 — llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
- CVE-2024-2952 — Server-Side Template Injection in BerriAI/litellm
- CVE-2024-1883 — Reflected XSS in PaperCut NG/MF