CVE-2026-27944
CRITICAL EXPLOITED NUCLEINginx UI <2.3.3 - Info Disclosure
Title source: llmDescription
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
Exploits (7)
github
WORKING POC
41 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/2026/nginxUi-CVE-2026-27944-AuthenticationMiss.py
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-27944
Nuclei Templates (1)
Nginx UI < 2.3.3 - Information Disclosure
CRITICALVERIFIEDby omarkurt
Shodan:
http.title:"nginx ui"
FOFA:
title="nginx ui"
Scores
CVSS v3
9.8
EPSS
0.0740
EPSS Percentile
91.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2026-03-19
CWE
CWE-311
CWE-306
Status
published
Products (2)
0xJacky/nginx-ui
< 2.3.3
nginxui/nginx_ui
< 2.3.3
Published
Mar 05, 2026
Tracked Since
Mar 06, 2026