← All CVEs NewScan detects
medium

CVE-2026-93964

nginx-proxy-manager through 2.15.1: internalCertificate.validate mishandles an uploaded certificate bundle

Severity
medium
Affected product
Nginx Proxy Manager
Affected versions
Nginx Proxy Manager ≤ 2.15.1
Added to NewScan
2026-09-20
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Nginx Proxy Manager from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-20 (/daily-cve). 5.5 and administrator-authenticated - the certificate upload is behind the admin UI - which is why it is medium and not higher; recorded because nginx-proxy-manager is overwhelmingly deployed as the front door of a self-hosted estate, so its admin plane is the pivot into everything behind it. NO `fixed_in`, on the Powerkit precedent: 2.15.1 is the vendor-stated affected bound AND the release jc21/nginx-proxy-manager:latest was serving when this was measured on 2026-09-20, so there is no published patch level to assert and the row declines to invent one. Add `fixed_in` once a fixed release exists. VERSION SOURCE is the tech_signatures "Nginx Proxy Manager" row added in the same batch, measured the same day: GET /api/ answers anonymously with {"status":"OK","setup":false,"version":{"major":2,"minor":15,"revision":1}} while every other /api path 404s unauthenticated. INERT ON EXISTING INSTALLS until the next release: that structured version document needs techdb.match_version's group-joining change to read as 2.15.1 at all, so the row alone does nothing until the image ships. Version-match only: the confirming action would upload a certificate to a stranger's proxy.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →