Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup
ID: 88f86e95-60d6-5275-aae6-17de1d331ae2
STIX ID: report--88f86e95-60d6-5275-aae6-17de1d331ae2
Feed Name: cybersecurityNews.com
**Critical Nginx UI vulnerability (CVE-2026-27944):** An unauthenticated backup endpoint exposes encrypted backup archives and returns the AES-256 key and IV in the X-Backup-Security HTTP response header, enabling attackers to download and decrypt full system backups (including database credentials, configuration files, SSL keys and certificates). A public PoC is available; immediate mitigation is upgrading Nginx UI to 2.3.3 and blocking or restricting access to /api/backup and management interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
