logo

Public PoC Exploit and Full Details Disclosed for Nginx UI’s 9.4 CVSS Backup Flaw

ID: dfc4e461-689f-52f1-9103-fd241dab55f5

STIX ID: report--dfc4e461-689f-52f1-9103-fd241dab55f5

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed a critical vulnerability (CVE-2026-33026, CVSS 9.4) in Nginx UI's backup/restore system where the backup encryption key/IV and integrity metadata are tied together, allowing an attacker with the backup token to decrypt, modify, recompute hashes, and re-encrypt backups so tampered archives appear legitimate; a public PoC exists and users are urged to upgrade to Nginx UI 2.3.4 and ensure restore aborts on hash verification failure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.