CVE-2026-27944

CRITICAL EXPLOITED NUCLEI

Nginx UI <2.3.3 - Info Disclosure

Title source: llm

Description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

Exploits (7)

github WORKING POC 41 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/2026/nginxUi-CVE-2026-27944-AuthenticationMiss.py
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-27944
nomisec WORKING POC 3 stars
by NULL200OK · poc
https://github.com/NULL200OK/CVE-2026-27944
nomisec WORKING POC
by Skynoxk · poc
https://github.com/Skynoxk/CVE-2026-27944
nomisec SCANNER
by NULL200OK · poc
https://github.com/NULL200OK/-nginxui_discover
nomisec WORKING POC
by weefunker · poc
https://github.com/weefunker/CVE-2026-27944-Lab

Nuclei Templates (1)

Nginx UI < 2.3.3 - Information Disclosure
CRITICALVERIFIEDby omarkurt
Shodan: http.title:"nginx ui"
FOFA: title="nginx ui"

Scores

CVSS v3 9.8
EPSS 0.0740
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-03-19
CWE
CWE-311 CWE-306
Status published
Products (2)
0xJacky/nginx-ui < 2.3.3
nginxui/nginx_ui < 2.3.3
Published Mar 05, 2026
Tracked Since Mar 06, 2026