Critical Nginx UI flaw CVE-2026-27944 exposes server backups
ID: 5e8aebd6-a4c4-5615-a326-15825af02e71
STIX ID: report--5e8aebd6-a4c4-5615-a326-15825af02e71
Feed Name: Security Affairs
A critical unauthenticated flaw in Nginx UI (CVE-2026-27944, CVSS 9.8) lets attackers access the /api/backup endpoint to download full system backups while the server discloses the AES-256 encryption key and IV in the X-Backup-Security response header, allowing immediate decryption of sensitive data including credentials, session tokens, SSL private keys, and configuration files; the advisory includes a PoC and recommends removing public exposure of management interfaces, using VPNs/IP allowlisting, MFA, and regular API security reviews.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
