Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
| Vendors & Products |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Bypass Enables Private Key Retrieval in Nginx Proxy Manager |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Bypass Enables Private Key Retrieval in Nginx Proxy Manager |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Mon, 15 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T18:05:28.642Z
Reserved: 2026-06-07T00:00:00.000Z
Link: CVE-2026-50892
Updated: 2026-06-16T18:05:22.403Z
Status : Awaiting Analysis
Published: 2026-06-15T20:16:32.210
Modified: 2026-06-16T19:17:00.587
Link: CVE-2026-50892
No data.
OpenCVE Enrichment
Updated: 2026-06-19T09:35:46Z