logo

CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access

ID: ae9a529f-adb0-59a5-8ad1-e255c10e6b11

STIX ID: report--ae9a529f-adb0-59a5-8ad1-e255c10e6b11

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CVE-2026-33032 is a critical (CVSS 9.8) nginx-ui vulnerability allowing unauthenticated attackers to bypass authentication on the /mcp_message endpoint; exploitation can be achieved in seconds with two HTTP requests, enabling full Nginx server takeover (config changes, service restarts, traffic interception). The issue is being actively exploited and was fixed in nginx-ui v2.3.4 by adding the missing authentication check.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.