CVE-2026-33027: 
Nginx UI vulnerability analysis and mitigation

Overview

CVE-2026-33027 is a path traversal vulnerability in nginx-ui (the web-based Nginx configuration management UI) that allows an authenticated user to recursively delete the entire /etc/nginx configuration directory, resulting in a Denial of Service. It affects all nginx-ui versions up to and including v2.3.3, with v2.3.4 being the first patched release. The vulnerability was published on March 28, 2026, and added to the GitHub Advisory Database on March 30, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Security Advisory).

Technical details

The root cause is a combination of three design flaws classified under CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path). First, the path validation logic does not properly reject URL-encoded traversal sequences, allowing double-encoded payloads such as ..%252F to bypass shallow input filters. Second, the GetConfPath clamping mechanism — intended to confine operations within the allowed configuration directory — instead resolves traversal attempts to the base Nginx configuration directory (/etc/nginx) rather than rejecting them outright. Third, the deletion handler in delete.go invokes Go's os.RemoveAll, which recursively removes entire directory trees without additional safeguards, meaning that when the clamped path resolves to /etc/nginx, the entire directory is deleted. Exploitation requires only a valid authenticated session and the ability to create and delete configuration entries via the nginx-ui web interface (Security Advisory, GitHub Advisory).

Impact

Successful exploitation results in the complete recursive deletion of the /etc/nginx directory, causing an immediate and total failure of the Nginx service due to missing configuration files. All web services and reverse-proxied applications relying on the affected Nginx instance become unavailable, constituting a Denial of Service. There is no confidentiality or integrity impact on data beyond the destruction of configuration files; however, manual restoration of the Nginx configuration is required before services can resume, potentially causing extended downtime (Security Advisory).

Exploitability

A proof-of-concept with detailed step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, confirmed as a real exploit with high confidence by Feedly threat intelligence. Exploitation requires a low-privilege authenticated account in nginx-ui, making it accessible to any user with login access. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.053–0.079%, placing it in the lower percentiles for near-term exploitation probability (Security Advisory, GitHub Advisory).

Exploitation steps

  1. Authenticate: Log into the nginx-ui web interface using any valid user account that has access to the "Manage Configs" section.
  2. Create a traversal-named folder: Navigate to "Manage Configs" and create a new Folder with the name ..%252F..%252F..%252F..%252Ftest. The double-encoded traversal sequences (%252F decodes to %2F, which further decodes to /) are used to bypass shallow input filters.
  3. Observe path resolution: Note that the backend resolves the crafted path to /etc/nginx due to the unsafe clamping mechanism in GetConfPath.
  4. Create a file as a workaround: Since direct creation with the payload name may be blocked, create a file named testing, save it, then rename it to ..%252F..%252F..%252F..%252Ftest.
  5. Trigger deletion: Return to the "Manage Configs" view and click "Delete" on the renamed file/folder entry.
  6. Confirm impact: Reload the nginx-ui website and verify that the /etc/nginx directory has been completely removed, rendering Nginx unable to start and all dependent web services unavailable (Security Advisory).

Indicators of compromise

  • Logs: nginx-ui application logs showing file/folder creation or rename operations with names containing %252F or other double-encoded sequences; deletion requests targeting paths that resolve to /etc/nginx.
  • File System: Absence of the /etc/nginx directory and all its contents (e.g., nginx.conf, sites-available/, sites-enabled/, conf.d/) following an unexpected deletion event.
  • Process/Service: Nginx service failing to start or crashing with errors indicating missing configuration files (e.g., nginx: configuration file /etc/nginx/nginx.conf test failed or No such file or directory).
  • Network: HTTP requests to the nginx-ui API deletion endpoint containing URL-encoded traversal sequences (%252F, %25252F) in path parameters (Security Advisory).

Mitigation and workarounds

The primary remediation is to upgrade nginx-ui to version v2.3.4 or later, which includes security patches addressing this and other vulnerabilities; the maintainer recommends all users update immediately (v2.3.4 Release). As interim workarounds: restrict nginx-ui access to trusted administrators only and enforce the principle of least privilege for all accounts. Additionally, implement filesystem-level access controls (e.g., read-only bind mounts for /etc/nginx where possible) and monitor for unexpected deletions in critical configuration directories. Backing up the /etc/nginx directory regularly will reduce recovery time if exploitation occurs (Security Advisory).

Community reactions

The vulnerability was reported by researcher dapickle and disclosed responsibly through GitHub's security advisory process. The nginx-ui maintainer (0xJacky) published the advisory and released a patched version (v2.3.4) promptly. Red Hat and openSUSE have both acknowledged the CVE in their security tracking systems. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (Security Advisory, v2.3.4 Release).

Additional resources


Source: This report was generated using AI

Related Nginx UI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44015CRITICAL9.9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 12, 2026
CVE-2026-42222CRITICAL9.8
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026
CVE-2026-42221CRITICAL9.8
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42238CRITICAL9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42223MEDIUM6.5
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management