CVE-2026-84315 is a vulnerability in Nginx UI whose fix was incomplete. The follow-on vulnerability, CVE-2026-107813, involves missing secure-session enforcement on sensitive cluster-management operations and is fixed in Nginx UI 2.5.0. The original vulnerability's technical mechanism, affected versions, and exploitation requirements are not established by the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The earlier Nginx UI vulnerability involved sensitive operations being accessible with JWT authentication alone, without fresh OTP step-up. Its fix added secure-session enforcement to several mutation routers and protected reload/restart MCP tools, but omitted the separate cluster router, resulting in CVE-2026-107813.
An earlier Nginx UI vulnerability whose incomplete remediation led to CVE-2026-107813. The content does not separately describe the earlier vulnerability's technical details, affected versions or remediation status.
An earlier Nginx UI vulnerability whose incomplete fix resulted in CVE-2026-107813. The reference does not separately describe the earlier vulnerability's affected versions, impact or exploitation status.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.