logo

Unauthenticated Nginx UI Flaw Leaks Decryption Keys and Server Secrets

ID: ddbf98c3-d33a-5c5a-9657-ef3872a2ecfa

STIX ID: report--ddbf98c3-d33a-5c5a-9657-ef3872a2ecfa

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-03-08

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** A critical vulnerability (CVE-2026-27944, CVSS 9.8) in Nginx UI allowed unauthenticated attackers to download full system backups from an unprotected /api/backup endpoint and decrypt them immediately because the AES-256 key and IV were returned in plaintext via an HTTP header; this exposes administrative credentials, SSL private keys, database secrets, and full configuration, and administrators are advised to update Nginx UI, rotate all potentially compromised secrets, and restrict access to management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.