/Vulnerability Library

Nginx UI < 2.3.3 - Information Disclosure

CVE-2026-27944
Verified

Description

Nginx UI < 2.3.3 contains an information disclosure vulnerability caused by unauthenticated access to /api/backup endpoint exposing encryption keys in X-Backup-Security header, letting unauthenticated attackers download and decrypt full system backups.

Severity

Critical

CVSS Score

9.8

Exploit Probability

1%

Affected Product

nginx-ui

Published Date

March 8, 2026

Template Author

omarkurt

CVE-2026-27944.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27944
CWE ID:
cwe-306

References

https://github.com/advisories/GHSA-g9w5-qffc-6762https://www.tenable.com/security/research/tra-2026-17https://vulnerabletarget.com/VT-2026-27944

Remediation Steps

Upgrade to version 2.3.3 or later.