Nginx UI Vulnerabilities Let Attackers Download Full System Backups
ID: e3eb5c14-15d4-5fe7-b0b6-e93eeda720ba
STIX ID: report--e3eb5c14-15d4-5fe7-b0b6-e93eeda720ba
Feed Name: GBHackers
Threat Score
**Critical unauthenticated backup disclosure in Nginx UI (CVE-2026-27944):** the /api/backup endpoint in Nginx UI (versions before 2.3.2) lacks authentication and returns the AES-256 key and IV in the X-Backup-Security header, allowing attackers to download and decrypt full system backups that contain databases, user credentials, session tokens, and SSL private keys; administrators should upgrade to 2.3.3, rotate credentials and certificates, and restrict admin interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
