logo

PoC Exploit Code Published for nginx-ui Backup Restore Security Flaw

ID: 465feaaa-65a7-5e09-ba67-0166a0baac82

STIX ID: report--465feaaa-65a7-5e09-ba67-0166a0baac82

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-01

Date Updated: 2026-07-21

Author: Divya

...
...

A critical vulnerability (CVE-2026-33026) in the nginx-ui backup restore process allows attackers to decrypt, modify, and re-encrypt backups because the client receives the AES key/IV and integrity metadata is trusted; a public PoC exists and successful exploitation enables insertion of backdoors and arbitrary command execution on affected hosts, so administrators should upgrade to nginx-ui 2.3.4 and implement server-side signed backup metadata.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.