Critical severity9.8NVD Advisory· Published Sep 27, 2024· Updated Jun 17, 2026
CVE-2024-46256
CVE-2024-46256
Description
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.11.3
Patches
Vulnerability mechanics
References
3- github.com/NginxProxyManager/nginx-proxy-manager/pull/4073/commits/c39d5433bcd13993def222bbb2b6988bbb810a05nvdPatch
- github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.11.3/backend/internal/certificate.jsnvdProduct
- github.com/NginxProxyManager/nginx-proxy-manager/commit/99cce7e2b0da2978411cedd7cac5fffbe15bc466nvdProduct
News mentions
0No linked articles in our index yet.