CVE-2024-46256 is a command injection vulnerability in NginxProxyManager version 2.11.3, specifically in the requestLetsEncryptSsl and requestLetsEncryptSslWithDnsChallenge functions (notably in backend/internal/certificate.js at line 830). The flaw allows an attacker to execute arbitrary commands on the server by exploiting the Add Let's Encrypt Certificate feature. The vulnerability can be triggered remotely, does not require authentication or user interaction, and is exploitable with low complexity. Proof-of-concept code and patch commits are publicly available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-46256, a remote code execution (RCE) vulnerability in Nginx Proxy Manager version 2.11.3 and earlier. The main exploit script, 'poc_cve_2024_46256_Tool.py', is a Python tool that interacts with the Nginx Proxy Manager API to authenticate as a user, check the version, test for vulnerability, and exploit the RCE by injecting commands into the certificate request process. The exploit requires valid credentials and leverages the domain_names field to inject shell commands, allowing the attacker to download and execute a reverse shell payload from an attacker-controlled HTTP server. The repository also includes a docker-compose file for setting up a vulnerable environment and a README with detailed usage instructions. The exploit is operational, providing a working RCE chain with a reverse shell payload, and is targeted specifically at Nginx Proxy Manager 2.11.3 (Linux, Docker-based deployments).
This repository contains a Python proof-of-concept exploit for CVE-2024-46256 (and CVE-2024-46257, as noted in the README). The exploit targets a web application's /api/nginx/certificates endpoint, abusing it to achieve remote code execution (RCE) via crafted JSON payloads. The exploit flow is as follows: the attacker authenticates to the target using valid credentials (obtained interactively), then sends payloads to download a netcat binary to /tmp/nc, makes it executable, and finally launches a reverse shell to an attacker-controlled server. The exploit is interactive, requiring user input for credentials and reverse shell parameters. The repository consists of a single Python exploit script and a README with usage instructions. The exploit is operational, providing a working RCE chain but requiring manual steps and valid credentials. Notable endpoints include /api/tokens (for authentication) and /api/nginx/certificates (the vulnerable endpoint). The exploit also references an external netcat binary hosted on GitHub.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.