This is a CWE-863 authorization flaw in which access checks for the advanced_config field do not enforce administrator-only editing. An authenticated non-admin user with manage permission for a host can provide arbitrary Nginx directives. The issue report and the proposed hardening change cover Proxy Host, Redirection Host, and 404 Host configurations. In the Nginx Proxy Manager template, advanced_config is inserted directly into the generated server block before the location configuration, so user-controlled content is processed as Nginx configuration rather than inert data. As a result, malicious directives such as alias can cause assigned hosts to serve unintended files or alter request routing. The available evidence does not establish the specific API route, detailed input-validation behavior, or separate limits imposed on individual Nginx directives.