logo

Public PoC Exploit Released for Nginx-UI Backup Restore Vulnerability

ID: 00269270-47da-5432-ad61-847785f52594

STIX ID: report--00269270-47da-5432-ad61-847785f52594

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical cryptographic design flaw (CVE-2026-33026) in Nginx-UI’s backup/restore allows attackers who obtain a backup security token to decrypt, modify, and re-encrypt backup archives—injecting malicious configuration (e.g., app.ini StartCmd) that can result in arbitrary command execution on the host; a public PoC exists and affected versions (≤2.3.3) should be upgraded to 2.3.4 immediately while developers should adopt server-side signed metadata and strict restore integrity checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.