CVE-2026-77180CWE-76

CVE-2026-77180

High · published September 2, 2026

CVSS v3.1
8.3
EPSS
0%
Percentile
23.1
In the wild
Unconfirmed
What it is

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives.

Impact:

An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The record
Technical detail
CVSS v3.1
8.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS
0.00307 · 23.1th percentile
Weakness
CWE-76 · Improper Neutralization of Equivalent Special Elements
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    NGINX Ingress Controller vulnerability
    cvelistv5