logo

Critical nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

ID: 71e708ca-369e-545a-b8bd-8d7aa4875df9

STIX ID: report--71e708ca-369e-545a-b8bd-8d7aa4875df9

Feed Name: The Cyber Express

Threat Score
92/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

CVE-2026-33032 is a critical (CVSS 9.8) authentication-bypass in nginx-ui that allows unauthenticated access to the /mcp_message endpoint (default IP whitelist is empty), enabling attackers to restart services, modify configs, and fully takeover Nginx servers; attackers are observed exploiting this in the wild and chain it with CVE-2026-27944 (unauthenticated /api/backup disclosure) to obtain node_secret and session credentials. Approximately 2,689 nginx-ui instances are publicly exposed; maintainers released nginx-ui 2.3.4 to remediate the issue and recommended enforcing authentication on /mcp_message, changing default allowlist to deny-by-default, restricting network access, or disabling MCP functionality.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.