Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
https://www.securityweek.com/exploited-vulnerability-exposes-nginx-servers-to-hacking/
https://www.darkreading.com/application-security/critical-mcp-integration-flaw-nginx-risk
https://github.com/Cosm3No1de/HTB-Snapped-Writeup
https://github.com/karimelsheikh1/HTB-Snapped-Writeup
https://github.com/bangsv/soc-detection-rules
https://github.com/keraattin/CVE-2026-33032
https://github.com/Shreda/CVE-2026-33032-nginx-ui-vuln-lab
https://github.com/mystichackers/CVE-2026
https://github.com/NULL200OK/-nginxui_discover
https://github.com/NULL200OK/CVE-2026-27944
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762
Published: 2026-03-05
Updated: 2026-03-10
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.22162
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored