How to find Nginx UI installations on your network
ID: 26bd09f5-e3e8-5aba-8018-42e7dc1ef572
STIX ID: report--26bd09f5-e3e8-5aba-8018-42e7dc1ef572
Feed Name: runZero Blog
Threat Score
Nginx UI has a critical vulnerability (CVE-2026-27944, CVSS 9.8) where the /api/backup endpoint lacks authentication and returns the AES-256 key and IV in plaintext, enabling unauthenticated attackers to download and decrypt full system backups containing credentials, session tokens, and SSL private keys. Affected versions are all releases prior to 2.3.3; users are advised to upgrade to 2.3.3 or later. A runZero query is provided to find potentially vulnerable systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
