# CVE-2026-66362

## Summary

- **CVE ID:** CVE-2026-66362
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-76
- **Published:** Sep 2, 2026
- **Last Modified:** Sep 3, 2026

## Description

Description:
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. 

Impact:
An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.

## Affected Products

- F5 — NGINX Gateway Fabric (2.5.0)

## References

- [CNA](https://my.f5.com/manage/s/article/K000162600)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 27.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._