CVE-2026-66362CWE-76

CVE-2026-66362

High · published September 2, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
24.1
In the wild
Unconfirmed
What it is

Description:

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping.

Impact:

An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
8.6 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00315 · 24.1th percentile
Weakness
CWE-76 · Improper Neutralization of Equivalent Special Elements
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:43Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    NGF vulnerability
    cvelistv5