logo

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

ID: 88f86e95-60d6-5275-aae6-17de1d331ae2

STIX ID: report--88f86e95-60d6-5275-aae6-17de1d331ae2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical Nginx UI vulnerability (CVE-2026-27944):** An unauthenticated backup endpoint exposes encrypted backup archives and returns the AES-256 key and IV in the X-Backup-Security HTTP response header, enabling attackers to download and decrypt full system backups (including database credentials, configuration files, SSL keys and certificates). A public PoC is available; immediate mitigation is upgrading Nginx UI to 2.3.3 and blocking or restricting access to /api/backup and management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.