PT-2026-29091 · 0Xjacky · Nginx-Ui
F1Vet
·
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2026-33030
CVSS v3.1
8.8
High
| AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model struct lacks a user id field, and all resource endpoints perform queries by ID without verifying user ownership, enabling complete authorization bypass in multi-user environments. At time of publication, there are no publicly available patches.
Fix
IDOR
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nginx-Ui