logo

How to find Nginx UI installations on your network

ID: 26bd09f5-e3e8-5aba-8018-42e7dc1ef572

STIX ID: report--26bd09f5-e3e8-5aba-8018-42e7dc1ef572

Feed Name: runZero Blog

Threat Score
85/100

Date Published: 2026-03-09

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

Nginx UI has a critical vulnerability (CVE-2026-27944, CVSS 9.8) where the /api/backup endpoint lacks authentication and returns the AES-256 key and IV in plaintext, enabling unauthenticated attackers to download and decrypt full system backups containing credentials, session tokens, and SSL private keys. Affected versions are all releases prior to 2.3.3; users are advised to upgrade to 2.3.3 or later. A runZero query is provided to find potentially vulnerable systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.