CVE-2026-33026PoC(nginxui / nginx_ui)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nginxui nginx_ui systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-312CWE-347CWE-354

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 6 mentions (2026-03-31); latest day: 1
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline13 mentions / 6d
02356Mentions · 2026-03-30: 1Mentions · 2026-03-31: 6Mentions · 2026-04-01: 2Mentions · 2026-04-02: 1Mentions · 2026-04-03: 2Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-03-31: 2PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-08: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 1Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-08: 103-3003-3104-0104-0204-0304-08
Signal classification4 categories
PoC
646.2%
Disclosure
538.5%
General
17.7%
Patch
17.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-316
Disclosure4PoC2
2026-04-012
PoC2
2026-04-021
PoC1
2026-04-032
General1Patch1
2026-04-081
PoC1
Full discourse13 posts
  • Gray Hats@the_yellow_fall
    PoC

    Public PoC exploit and details are out for Nginx UI’s 9.4 CVSS backup flaw (CVE-2026-33026). Attackers can hijack servers via tampered backups. Update now! #NginxUI #CVE #PoC #CyberSecurity #InfoSec #RCE #ExploitDisclosed #PatchAlert #ServerSecurity https://securityonline.info/nginx-ui-backup-vulnerability-poc-disclosed-cve-2026-33026/ https://t.co/i1Qu2ayuKb

    Post summary

    A public proof‑of‑concept exploit for CVE‑2026‑33026 in Nginx UI has been disclosed, and users are urged to apply updates to mitigate server hijacking via tampered backups.

    0901641.0K
    12.3K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    PoC

    🚨 Upozorňujeme na zranitelnosti v Nginx UI, CVE-2026-33032 a CVE-2026-33026. V Nginx UI byly identifikovány dvě závažné chyby, které v kombinaci umožňují neautentizovaným útočníkům vzdáleně převzít plnou kontrolu nad postiženým systémem nebo dosáhnout perzistence. První zranitelnost (CVE-2026-33032) spočívá v obejití autentizace v rámci integrace Model Context Protocol (MCP), kde endpoint /mcp_message není chráněn přihlášením a spoléhá se pouze na IP whitelist, přičemž prázdný whitelist je chybně vyhodnocen jako „allow all“. To umožňuje libovolnému vzdálenému útočníkovi bez autentizace volat MCP nástroje a plně ovládat konfiguraci Nginx, spravovat služby, manipulovat s provozem, získávat citlivé konfigurace, přihlašovací údaje a způsobit narušení dostupnosti až úplné převzetí systému; zranitelnost se týká všech verzí Nginx UI a existuje veřejně dostupný proof-of-concept exploit. Druhá zranitelnost (CVE-2026-33026) je způsobena chybným kryptografickým návrhem mechanismu zálohování a obnovy, kdy jsou zálohy šifrovány pomocí AES-256-CBC, avšak šifrovací klíč i inicializační vektor jsou vystaveny klientovi a metadata integrity jsou šifrována stejným klíčem, což útočníkovi umožňuje zálohy libovolně upravovat, znovu dopočítat kontrolní hodnoty a podvrhnout je jako platné. Tato zranitelnost se týká verzí Nginx UI do verze 2.3.3 včetně. 📌 Doporučujeme aktualizovat na Nginx UI verze 2.3.4 nebo novější a zároveň omezit dostupnost rozhraní správy pouze na důvěryhodné prostředí.

    Post summary

    The post alerts about two critical vulnerabilities in Nginx UI, confirms a publicly available proof‑of‑concept, provides detailed technical information, and recommends updating to version 2.3.4 or later while restricting management access.

    02000469
    4.2K followersView on X
  • iototsecnews@iototsecnews
    PoC

    nginx-ui の脆弱性 CVE-2026-33026 が FIX:PoC エクスプロイト・コードも登場 https://iototsecnews.jp/2026/04/01/poc-exploit-code-published-for-nginx-ui-backup-restore-security-flaw/ nginx-ui のバックアップ復元機能に存在する、深刻な脆弱性 CVE-2026-33026 について解説する記事です。この問題の原因は、バックアップの鍵をサーバ側で隠し持たず、クライアント側に渡してしまうという、信頼モデルの設計ミスにあります。通常、データの改竄を防ぐための整合性チェック (ハッシュ値) などは、攻撃者が手出しできない秘密の鍵で守られるべきです。しかし、この脆弱性を悪用する攻撃者は、データの暗号化に使う鍵や初期化ベクトル (IV) をクライアントから引き出すことが可能になります。そのため、バックアップの中身である Nginx の設定ファイルなどを攻撃者が書き換え、同じ鍵を使って作り直し、再暗号化することが可能となっています。ご利用のチームは、ご注意ください。 #CVE202633026 #nginx #nginxui #PoC #Vulnerability

    Post summary

    The post announces a serious vulnerability (CVE-2026-33026) in nginx-ui's backup restore feature and confirms that a proof‑of‑concept and exploit code have been released, allowing attackers to retrieve encryption keys and modify server configuration.

    01000113
    483 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical NginxUI vulnerability (CVE-2026-33026) allows attackers to manipulate backups and execute arbitrary code. Immediate upgrade to version 2.3.4 recommended. https://thedailytechfeed.com/critical-nginx-ui-vulnerability-cve-2026-33026-allows-full-system-compromise-via-backup-exploit/ #Security #Vulnerability #Exploit #Upgrade #Nginx #Backup #CVE #Attack #Code #System #Hack #Patch #Update #Tech #Threat #Malware #Risk #Cyber #Protection #IT

    Post summary

    The tweet alerts to CVE-2026-33026, a backup‑based code‑execution flaw in NginxUI, and urges an immediate upgrade to v2.3.4 but provides no PoC or exploitation evidence.

    0100013
    271 followersView on X
  • z3n@zench4n
    General

    Final tip: Treat AI agents like privileged users. Default credentials (CVE-2026-33026) and weak auth (CVE-2026-5281) will burn you. Assume every agent endpoint is a potential breach point.

    Post summary

    The message offers a cautionary tip about default credentials and weak authentication in AI agents, referencing two CVEs but providing no technical details, exploitation evidence, or mitigation information.

    1000020
    1.5K followersView on X
  • キタきつね@foxbook
    PoC

    Nginx UIの9.4 CVSSバックアップ脆弱性に対する公開PoCエクスプロイトと詳細情報が公開されました Public PoC Exploit and Full Details Disclosed for Nginx UI’s 9.4 CVSS Backup Flaw #DailyCyberSecurity (Mar 31) https://securityonline.info/nginx-ui-backup-vulnerability-poc-disclosed-cve-2026-33026/

    Post summary

    A proof‑of‑concept exploit and detailed information for Nginx UI’s 9.4 CVSS backup vulnerability (CVE‑2026‑33026) have been publicly disclosed, with no indication of active exploitation or available patch.

    00010456
    4.8K followersView on X
  • Syed Aquib@syedaquib77
    PoC

    ⚠️ **Vulnerability Alert:** Vim modeline sandbox bypass (arbitrary OS command execution) & Nginx-UI backup-restore tampering 🆔 **CVE-2026-34982** 🆔 **CVE-2026-33026** | 📊 CVSS: 9.1 (CRITICAL 🔴) | 📈 EPSS: 1.67% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** unspecified Vim versions (modeline sandbox bypass), nginx-ui < 2.3.4 🔧 **Fixed Versions:** (unknown), nginx-ui 2.3.4 🫨 **Attack Vectors:** - Vim: local file modeline crafted to execute OS commands when opened (local user opens file) - Nginx-UI: backup restore tampering via manipulated encrypted backup archives (network-exposed service; requires high privileges) 📝 **Summary:** A Vim modeline sandbox bypass can execute arbitrary OS commands when a crafted file is opened, risking system compromise under the user context. Nginx-UI backup-restore tampering allows malicious configs to be injected during restore, enabling persistent compromise; nginx-ui is patched in 2.3.4. 📈 **Impact Scope:** Arbitrary command execution on systems where vulnerable Vim is used; persistent configuration changes and service compromise on nginx-ui instances restored from tampered backups; potential for lateral movement and privilege escalation. 🛡️ **Recommended Actions:** - Disable Vim modeline processing (set modeline=0 and modelines=0) and avoid opening untrusted files. - Upgrade nginx-ui to 2.3.4 immediately and verify backup integrity before any restore. 🪢 **Related Resources:** - https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-fhh2-gg7w-gwpq - https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4 🏷 **Tags:** #Cybersecurity #Vim #nginx-ui

    Post summary

    The alert announces CVE‑2026‑34982 and CVE‑2026‑33026, provides proof‑of‑concept details, outlines how attacks work, and recommends disabling modeline processing and upgrading nginx‑ui to 2.3.4.

    00000102
    276 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `nginx-ui` is affected by CVE-2026-33026, a critical vulnerability allowing tampering with encrypted backups during restoration. Review backup integrity and access controls. #nginx #security #CVE https://www.pulsepatch.io/posts/cve-2026-33026-nginx-ui-backup-tampering

    Post summary

    CVE-2026-33026 is disclosed as a critical nginx‑ui vulnerability that allows tampering with encrypted backups, but no PoC, exploit, patch, or active exploitation information is provided.

    0000031
    6 followersView on X
  • moton@moton
    PoC

    Public PoC Exploit and Full Details Disclosed for Nginx UI’s 9.4 CVSS Backup Flaw - https://securityonline.info/nginx-ui-backup-vulnerability-poc-disclosed-cve-2026-33026/

    Post summary

    The post announces that a public proof‑of‑concept exploit and full technical details for the Nginx UI 9.4 backup flaw (CVE‑2026‑33026) have been disclosed, with no indications of active exploitation, patches, or debunking.

    0000052
    657 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical nginx-ui flaw CVE-2026-33026 could let attackers tamper with backups and impact configuration integrity. 🔗 https://vulert.com/vuln-db/CVE-2026-33026 #CyberSecurity #nginxui #AppSec #DevSecOps #OpenSourceSecurity https://t.co/T8lV7DrNxu

    Post summary

    The tweet announces a critical flaw in nginx-ui (CVE‑2026‑33026) that may let attackers tamper with backups and configuration, but provides no PoC, exploit code, or patch information.

    0000032
    122 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33026 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted bac… https://www.cve.org/CVERecord?id=CVE-2026-33026 ----- Traducción: CVE-2026-33026 Ngi… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33026, describing a vulnerability in the Nginx UI backup‑restore mechanism that allows tampering with encrypted backups, but provides no evidence of a PoC, exploit, or patch.

    0000025
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33026 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted bac… https://www.cve.org/CVERecord?id=CVE-2026-33026

    Post summary

    The post announces a discovered flaw in Nginx UI’s backup restoration process (pre‑2.3.4) that permits tampering with encrypted backups, highlighting the vulnerability without providing a PoC, exploit, or mitigation.

    00000150
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33026: nginx-ui Backup Restore Allows T... Encrypted backups mean nothing when restore logic doesn't verify integrity - classic crypto implementation fail turning... https://zerodaysignal.com/vulnerability/CVE-2026-33026 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑33026 for nginx‑ui, noting a backup‑restore integrity flaw, but provides no PoC, patch, or evidence of exploitation.

    0000087
    176 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more