CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access
ID: ae9a529f-adb0-59a5-8ad1-e255c10e6b11
STIX ID: report--ae9a529f-adb0-59a5-8ad1-e255c10e6b11
Feed Name: Security Affairs
Threat Score
CVE-2026-33032 is a critical (CVSS 9.8) nginx-ui vulnerability allowing unauthenticated attackers to bypass authentication on the /mcp_message endpoint; exploitation can be achieved in seconds with two HTTP requests, enabling full Nginx server takeover (config changes, service restarts, traffic interception). The issue is being actively exploited and was fixed in nginx-ui v2.3.4 by adding the missing authentication check.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
