CVE-2026-60062
published 2026-07-15CVE-2026-60062: The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure…
PriorityP342medium6.4CVSS 3.1
AVNACLPRLUINSCCLILAN
EPSS
0.30%
22.1th percentile
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary.
Impact:
A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_agent | >= 2.0.0 < 2.47.0 | 2.47.0 |
| f5 | nginx_agent | >= 2.37.0 < 2.46.7 | 2.46.7 |
| f5 | nginx_instance_manager | >= 2.17.1 < * | * |
| f5 | nginx_instance_manager | >= 2.17.1 < 2.22.2 | 2.22.2 |
| f5 | nginx_instance_manager | >= 2.22.0 < 2.22.2 | 2.22.2 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2026-60062: The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files...
vendor_f5·2026-07-15·CVSS 6.4
CVE-2026-60062 [MEDIUM] CWE-22 CVE-2026-60062: The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files...
CVE-2026-60062: The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files...
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary.
Impact:
A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Advisory Articles: K000161971
F5 References:
VulDB
F5 NGINX Agent/NGINX Instance Manager Configuration information disclosure
vuldb·2026-08-07·CVSS 6.4
CVE-2026-60062 [MEDIUM] F5 NGINX Agent/NGINX Instance Manager Configuration information disclosure
A vulnerability classified as problematic has been found in F5 NGINX Agent and NGINX Instance Manager. This issue affects some unknown processing of the component Configuration. This manipulation causes information disclosure.
This vulnerability appears as CVE-2026-60062. The attack may be initiated remotely. There is no available exploit.
GHSA
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory.
ghsa_unreviewed·2026-07-15
CVE-2026-60062 [MEDIUM] CWE-22 The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory.
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary.
Impact:
A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-15
Published