CVE-2026-27944: 
Nginx UI vulnerability analysis and mitigation

Overview

CVE-2026-27944 is a critical unauthenticated backup download vulnerability in Nginx UI (nginx-ui) that allows any remote attacker to download a full system backup and immediately decrypt it. The /api/backup endpoint is exposed without any authentication middleware, and the AES-256-CBC encryption keys required to decrypt the backup are disclosed in plaintext via the X-Backup-Security HTTP response header. All versions of nginx-ui prior to 2.3.3 are affected. The vulnerability was disclosed on March 5, 2026, and patched in version 2.3.3. It carries a CVSS v3.1 base score of 9.8 (Critical) (Github Advisory, GHSA Advisory).

Technical details

The vulnerability stems from two compounding flaws classified as CWE-306 (Missing Authentication for Critical Function) and CWE-311 (Missing Encryption of Sensitive Data). In api/backup/router.go, the /api/backup GET endpoint is registered without any authentication middleware — in stark contrast to the /api/restore endpoint, which correctly enforces middleware. Additionally, in api/backup/backup.go, the CreateBackup function concatenates the Base64-encoded AES-256 key (32 bytes) and IV (16 bytes) as key:iv and transmits them in the X-Backup-Security response header alongside the encrypted ZIP archive. The backup archive contains database.db (user credentials, session tokens), app.ini (application secrets), SSL private keys and certificates, and Nginx configuration files. No preconditions are required — the attack is fully unauthenticated and exploitable over the network with a single HTTP GET request (Github Advisory, GHSA Advisory).

Impact

Successful exploitation gives an unauthenticated attacker complete access to all sensitive data managed by the Nginx UI instance, including plaintext user credentials, active session tokens, SSL/TLS private keys, and all Nginx server configurations. Compromised SSL private keys enable passive TLS decryption of historical and future traffic, while stolen credentials and session tokens allow direct administrative access to the Nginx UI and potentially to downstream systems. The combination of credential theft and SSL key exposure creates significant risk for lateral movement, impersonation, and full server takeover (Github Advisory, Black Hat Ethical Hacking).

Exploitability

A complete, runnable Python proof-of-concept exploit is publicly available in the official security advisory, performing end-to-end unauthenticated backup download, key extraction from the response header, and AES-256-CBC decryption using pycryptodome (GHSA Advisory). Additional PoC repositories have appeared on GitHub (e.g., Skynoxk/CVE-2026-27944, Goultarde/CVE-2026-27944-poc, jake-young-dev/CVE-2026-27944), and the vulnerability has been incorporated into Vulhub lab environments and ProjectDiscovery Nuclei templates. Active exploitation has been reported by multiple sources, including Black Hat Ethical Hacking and The Hacker News, with exploitation described as imminent or confirmed in the wild (Black Hat Ethical Hacking, The Hacker News). The EPSS score is approximately 7.3% (92nd percentile), indicating elevated exploitation probability. The vulnerability is also featured in Hack The Box's "Snapped" machine, further broadening attacker familiarity (Github Advisory, HTB Blog). No specific threat actor attribution has been publicly confirmed. CISA KEV catalog status is not confirmed in available sources.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Nginx UI instances using Shodan, Censys, or ProjectDiscovery's Nuclei templates targeting the /api/backup endpoint on common ports (e.g., 9000).
  2. Send unauthenticated GET request: Issue a plain HTTP GET request to http://<target>:<port>/api/backup with no authentication headers or cookies required.
  3. Extract encryption keys from response header: Parse the X-Backup-Security response header, which contains the AES-256 key and IV in base64_key:base64_iv format (e.g., e5eWtUkqVEIixQjh253kPYe3cpzdasxiYTbOFHm9CJ4=:7XdVSRcgYfWf7C/J0IS8Cg==).
  4. Save the encrypted backup: Write the binary ZIP response body to disk (e.g., backup.bin).
  5. Decrypt the backup: Using the extracted key and IV, perform AES-256-CBC decryption (with PKCS#7 unpadding via pycryptodome) on each encrypted file within the archive (nginx-ui.zip, nginx.zip, hash_info.txt).
  6. Extract sensitive data: Unzip the decrypted archives to obtain database.db (user credentials, session tokens), app.ini (application secrets), SSL private keys, and Nginx configuration files.
  7. Leverage obtained credentials: Use extracted credentials or session tokens to authenticate to the Nginx UI admin panel, or use SSL private keys to decrypt captured TLS traffic and pivot to further systems (GHSA Advisory, Github Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /api/backup from external or unexpected IP addresses; responses containing the X-Backup-Security header observed in proxy or WAF logs; large binary (ZIP) downloads from the Nginx UI port (commonly 9000) without a preceding authenticated session.
  • Logs: Nginx UI access logs showing GET /api/backup HTTP/1.1 with a 200 response code from unfamiliar source IPs; absence of any authentication token or session cookie in the request headers for this endpoint.
  • File System: Unexpected backup files (e.g., backup-*.zip) created or accessed on the server; new or modified files in the Nginx UI data directory shortly after a suspicious /api/backup request.
  • Behavioral: Subsequent login attempts using credentials that match those stored in database.db; use of SSL private keys from the backup to establish TLS connections from unknown hosts; administrative actions in Nginx UI from IP addresses not previously associated with legitimate administrators (GHSA Advisory, Black Hat Ethical Hacking).

Mitigation and workarounds

Upgrade nginx-ui to version 2.3.3 or later, which adds authentication middleware to the /api/backup endpoint and removes encryption key disclosure from response headers (Github Advisory). As an immediate workaround prior to patching, restrict network access to the Nginx UI port (commonly 9000) using firewall rules or web server ACLs to trusted IP ranges only. After patching, rotate all credentials, session tokens, and SSL certificates that may have been present in any backup generated by a vulnerable version. Review web server and application access logs for unauthorized requests to /api/backup and treat any such access as a confirmed compromise requiring full credential rotation (GHSA Advisory, CCB Belgium).

Community reactions

The vulnerability received broad coverage across the security community shortly after disclosure on March 5, 2026. Security Affairs, The Hacker News, GBHackers, CyberSecurityNews, and The Cyber Express all published dedicated articles highlighting the critical severity and ease of exploitation (The Hacker News, Security Affairs). Belgium's Centre for Cybersecurity (CCB) issued a formal advisory warning of the risk of full system compromise (CCB Belgium). Rapid7 and runZero published threat intelligence analyses, and Recorded Future included the CVE in its March 2026 CVE landscape report (Recorded Future). The vulnerability was also featured in Hack The Box's "Snapped" machine, generating significant community discussion on Reddit, Mastodon, and Bluesky, with researchers noting the unusual design flaw of disclosing decryption keys in the same response as the encrypted data (HTB Blog).

Additional resources


Source: This report was generated using AI

Related Nginx UI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44015CRITICAL9.9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 12, 2026
CVE-2026-42222CRITICAL9.8
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026
CVE-2026-42221CRITICAL9.8
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42238CRITICAL9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42223MEDIUM6.5
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management