
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33027 is a path traversal vulnerability in nginx-ui (the web-based Nginx configuration management UI) that allows an authenticated user to recursively delete the entire /etc/nginx configuration directory, resulting in a Denial of Service. It affects all nginx-ui versions up to and including v2.3.3, with v2.3.4 being the first patched release. The vulnerability was published on March 28, 2026, and added to the GitHub Advisory Database on March 30, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Security Advisory).
The root cause is a combination of three design flaws classified under CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path). First, the path validation logic does not properly reject URL-encoded traversal sequences, allowing double-encoded payloads such as ..%252F to bypass shallow input filters. Second, the GetConfPath clamping mechanism — intended to confine operations within the allowed configuration directory — instead resolves traversal attempts to the base Nginx configuration directory (/etc/nginx) rather than rejecting them outright. Third, the deletion handler in delete.go invokes Go's os.RemoveAll, which recursively removes entire directory trees without additional safeguards, meaning that when the clamped path resolves to /etc/nginx, the entire directory is deleted. Exploitation requires only a valid authenticated session and the ability to create and delete configuration entries via the nginx-ui web interface (Security Advisory, GitHub Advisory).
Successful exploitation results in the complete recursive deletion of the /etc/nginx directory, causing an immediate and total failure of the Nginx service due to missing configuration files. All web services and reverse-proxied applications relying on the affected Nginx instance become unavailable, constituting a Denial of Service. There is no confidentiality or integrity impact on data beyond the destruction of configuration files; however, manual restoration of the Nginx configuration is required before services can resume, potentially causing extended downtime (Security Advisory).
A proof-of-concept with detailed step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, confirmed as a real exploit with high confidence by Feedly threat intelligence. Exploitation requires a low-privilege authenticated account in nginx-ui, making it accessible to any user with login access. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.053–0.079%, placing it in the lower percentiles for near-term exploitation probability (Security Advisory, GitHub Advisory).
..%252F..%252F..%252F..%252Ftest. The double-encoded traversal sequences (%252F decodes to %2F, which further decodes to /) are used to bypass shallow input filters./etc/nginx due to the unsafe clamping mechanism in GetConfPath.testing, save it, then rename it to ..%252F..%252F..%252F..%252Ftest./etc/nginx directory has been completely removed, rendering Nginx unable to start and all dependent web services unavailable (Security Advisory).%252F or other double-encoded sequences; deletion requests targeting paths that resolve to /etc/nginx./etc/nginx directory and all its contents (e.g., nginx.conf, sites-available/, sites-enabled/, conf.d/) following an unexpected deletion event.nginx: configuration file /etc/nginx/nginx.conf test failed or No such file or directory).%252F, %25252F) in path parameters (Security Advisory).The primary remediation is to upgrade nginx-ui to version v2.3.4 or later, which includes security patches addressing this and other vulnerabilities; the maintainer recommends all users update immediately (v2.3.4 Release). As interim workarounds: restrict nginx-ui access to trusted administrators only and enforce the principle of least privilege for all accounts. Additionally, implement filesystem-level access controls (e.g., read-only bind mounts for /etc/nginx where possible) and monitor for unexpected deletions in critical configuration directories. Backing up the /etc/nginx directory regularly will reduce recovery time if exploitation occurs (Security Advisory).
The vulnerability was reported by researcher dapickle and disclosed responsibly through GitHub's security advisory process. The nginx-ui maintainer (0xJacky) published the advisory and released a patched version (v2.3.4) promptly. Red Hat and openSUSE have both acknowledged the CVE in their security tracking systems. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (Security Advisory, v2.3.4 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."