CVE-2026-33026: 
Nginx UI vulnerability analysis and mitigation

Overview

CVE-2026-33026 is a critical backup tampering vulnerability in nginx-ui (a web-based Nginx management interface) that allows authenticated attackers with access to a backup security token to decrypt, modify, and re-encrypt backup archives, injecting malicious configuration that can lead to arbitrary command execution on the host. It affects all nginx-ui versions up to and including 2.3.3, with version 2.3.4 containing the fix. The vulnerability was published on March 28–30, 2026, and carries a CVSS v4 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.1 (Critical) (Github Advisory, Security Advisory).

Technical details

The root cause is a circular trust model in the backup system, classified under CWE-312 (Cleartext Storage of Sensitive Information), CWE-347 (Improper Verification of Cryptographic Signature), and CWE-354 (Improper Validation of Integrity Check Value). Backup archives are encrypted with AES-256-CBC, but the encryption key and IV are provided directly to the client as a "backup security token"; the integrity metadata file (hash_info.txt) is also encrypted with this same key. Because the attacker possesses the key, they can decrypt the archive, modify app.ini or other configuration files (e.g., setting StartCmd = bash), recompute SHA-256 hashes for the modified files, update hash_info.txt, and re-encrypt the entire bundle — producing a cryptographically valid but malicious backup. Critically, the restore process (restore.go) does not abort on hash mismatches and proceeds with restoration even when integrity warnings are raised, accepting attacker-controlled configuration (Security Advisory). This vulnerability is a regression from a prior related issue (GHSA-g9w5-qffc-6762 / CVE-2026-27944), which fixed unauthenticated backup access but left the underlying cryptographic design flaw unresolved (Github Advisory).

Impact

Successful exploitation allows an attacker to persistently tamper with nginx-ui application configuration, insert backdoors into nginx configuration files, and achieve arbitrary command execution on the host system. All three security pillars are fully compromised: confidentiality (access to credentials, SSL private keys, session tokens stored in the backup), integrity (attacker-controlled configuration applied to the system), and availability (potential service disruption or full system takeover). The scope change (CVSS S:C) indicates that compromise extends beyond the nginx-ui application itself to the underlying host and any services managed by nginx (Security Advisory).

Exploitability

A detailed proof-of-concept exploit with Python code is publicly available in the official security advisory, covering the full attack workflow from token extraction through malicious backup upload (Security Advisory). Feedly's threat intelligence classifies the exploit confidence as high and confirms it constitutes a real, actionable exploit. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.012% (0.000120), indicating low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires high privileges (access to the backup security token), which limits the attacker pool but does not eliminate risk in environments where backup tokens are shared or leaked (Github Advisory).

Exploitation steps

  1. Obtain the backup security token: As an authenticated user (or by leveraging the previously patched CVE-2026-27944 unauthenticated backup endpoint on unpatched older versions), generate a backup and capture the AES key and IV from the HTTP response headers (X-Backup-Security) or the .key file.
  2. Download the backup archive: Retrieve the backup ZIP file (e.g., backup-20260314-151959.zip) containing nginx-ui.zip, nginx.zip, and hash_info.txt.
  3. Decrypt the archive contents: Using the captured token (key_b64:iv_b64), decrypt each encrypted file using AES-256-CBC with the pycryptodome Python library, producing plaintext versions of nginx-ui.zip, nginx.zip, and hash_info.txt.
  4. Modify malicious configuration: Extract nginx-ui.zip and edit app.ini to inject a malicious directive (e.g., StartCmd = bash) or modify nginx configuration files to insert backdoors.
  5. Recompute integrity hashes: Re-compress the modified files, compute new SHA-256 hashes for each encrypted blob, and update hash_info.txt with the new hashes.
  6. Re-encrypt the bundle: Encrypt the modified nginx-ui.zip, nginx.zip, and updated hash_info.txt using the original AES key and IV, then package them into a new ZIP archive.
  7. Upload the tampered backup: Submit the crafted backup archive to the nginx-ui restore interface (POST /api/restore).
  8. Achieve arbitrary command execution: The restore process accepts the modified backup (ignoring any hash mismatch warnings) and applies the attacker-controlled configuration, resulting in arbitrary command execution on the host (Security Advisory).

Indicators of compromise

  • Network: Unusual POST requests to the nginx-ui restore endpoint (e.g., /api/restore) from unexpected source IPs or at unusual times; outbound connections from the nginx-ui host to unknown external IPs following a restore operation.
  • File System: Unexpected modifications to app.ini or nginx configuration files (e.g., nginx.conf, files under sites-enabled/) shortly after a backup restore; presence of new or modified backup ZIP files (backup_rebuild.zip) in accessible directories; unexpected shell scripts or web shells in the nginx-ui installation directory.
  • Logs: nginx-ui application logs showing a restore operation followed immediately by process execution anomalies; integrity verification warnings in restore logs that were not acted upon; access logs showing backup download and subsequent restore within a short time window.
  • Process: Unexpected child processes spawned by the nginx-ui process (e.g., bash, sh, curl, wget, python) following a restore event; new cron jobs or scheduled tasks created under the nginx-ui service account (Security Advisory).

Mitigation and workarounds

Upgrade nginx-ui to version 2.3.4 or later, which contains security patches addressing this vulnerability (v2.3.4 Release). The vendor recommends all users update immediately. As interim mitigations, restrict access to backup generation and the backup security token to the minimum necessary personnel, and implement network-level controls to limit who can access the nginx-ui restore interface. Additionally, consider implementing out-of-band integrity verification for backup archives independent of the encrypted metadata, and avoid sharing backup tokens across untrusted parties (Github Advisory).

Community reactions

The vulnerability received coverage from multiple cybersecurity news outlets including GBHackers, CyberPress, CyberSecurityNews, and The Daily Tech Feed, with several articles highlighting the public PoC exploit availability and the risk of arbitrary command execution. The Hacker News included it in a weekly recap. F5 Labs covered it in their weekly threat bulletin for April 22, 2026. The security community noted this as a regression from the previously patched CVE-2026-27944, underscoring the systemic nature of the cryptographic design flaw in nginx-ui's backup architecture (GBHackers, CyberSecurityNews).

Additional resources


Source: This report was generated using AI

Related Nginx UI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44015CRITICAL9.9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 12, 2026
CVE-2026-42222CRITICAL9.8
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026
CVE-2026-42221CRITICAL9.8
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42238CRITICAL9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42223MEDIUM6.5
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management