CVE-2026-33026

CRITICAL

nginx-ui Backup Restore Allows Tampering with Encrypted Backups

Title source: cna
STIX 2.1

Description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

References (2)

Core 2
Core References

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-312 CWE-347 CWE-354
Status published
Products (3)
0xJacky/Nginx-UI 0Go
0xJacky/nginx-ui < 2.3.4
nginxui/nginx_ui < 2.3.4
Published Mar 30, 2026
Tracked Since Mar 31, 2026