CVE-2026-40519
Last modified
CVE-2026-40519 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40519?
How severe is CVE-2026-40519?
How do I fix CVE-2026-40519?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40512Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-40514SmarterTools SmarterMail builds prior to 9610 contain a cryp…9.1
- CVE-2026-40515OpenHarness before commit bd4df81 contains a permission bypa…5.5
- CVE-2026-40516OpenHarness before commit bd4df81 contains a server-side req…6.3
- CVE-2026-40517radare2 prior to 6.1.4 contains a command injection vulnerab…8.4
- CVE-2026-40518ByteDance DeerFlow before commit 2176b2b contains a path tra…9.1
- CVE-2026-40520FreePBX api module version 17.0.8 and prior contain a comman…8.8
- CVE-2026-40521FrontAccounting before 2.4.20 contains a path traversal vuln…8.8
- CVE-2026-40522FrontAccounting before 2.4.20 contains a SQL injection vulne…7.1
- CVE-2026-40523FrontAccounting before 2.4.20 contains a SQL injection vulne…8.1
- CVE-2026-40524FrontAccounting before 2.4.20 contains a SQL injection vulne…8.1
- CVE-2026-40525OpenViking prior to version 0.3.9 contains an authentication…9.1
Are you affected by CVE-2026-40519?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
