logo

Critical Nginx UI flaw CVE-2026-27944 exposes server backups

ID: 5e8aebd6-a4c4-5615-a326-15825af02e71

STIX ID: report--5e8aebd6-a4c4-5615-a326-15825af02e71

Feed Name: Security Affairs

Threat Score
86/100

Date Published: 2026-03-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical unauthenticated flaw in Nginx UI (CVE-2026-27944, CVSS 9.8) lets attackers access the /api/backup endpoint to download full system backups while the server discloses the AES-256 encryption key and IV in the X-Backup-Security response header, allowing immediate decryption of sensitive data including credentials, session tokens, SSL private keys, and configuration files; the advisory includes a PoC and recommends removing public exposure of management interfaces, using VPNs/IP allowlisting, MFA, and regular API security reviews.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.