SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-60062

MEDIUM · CVSS 6.4 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The NGINX Agent's config_dirs directive is vulnerable, allowing low-privileged authenticated attackers to gain limited read and write access to files outside the designated secure directory. This could enable attackers to cross security boundaries and potentially compromise sensitive data. Organizations using NGINX, particularly those with remote access configurations, should prioritize addressing this vulnerability to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60062
Severity
MEDIUM
CVSS
6.4
EPSS
0.20%
Nginx

Original NVD Description

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Related CVEs

Other vulnerabilities affecting the same vendor(s)