PT-2026-29092 · Nginx-Ui+1 · Nginx-Ui+1

Yotampe-Pluto

·

Published

2026-03-28

·

Updated

2026-05-16

·

CVE-2026-33032

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.6
Description An authentication bypass exists in the Model Context Protocol (MCP) integration of Nginx UI. The software exposes two HTTP endpoints: '/mcp' and '/mcp message'. While '/mcp' requires both IP whitelisting and authentication via the AuthRequired() middleware, the '/mcp message' endpoint only applies IP whitelisting. Because the default IP whitelist is empty, the middleware treats this as "allow all," permitting any network attacker to invoke MCP tools without authentication. Additionally, the '/api/mcp/invoke' endpoint fails to verify session tokens.
This flaw allows remote attackers to achieve complete takeover of the Nginx service by performing actions such as restarting Nginx, creating, modifying, or deleting configuration files, and triggering automatic configuration reloads. Approximately 2,689 exposed instances have been identified worldwide, with active exploitation confirmed in the wild.
Recommendations Update to Nginx UI version 2.3.6 immediately. As a temporary workaround, disable the Nginx UI service entirely or block access to the management port at the network firewall.

Exploit

Fix

RCE

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-04537
CVE-2026-33032
GHSA-H6C2-X2M2-MWHF
GO-2026-4904
SUSE-SU-2026:1205-1

Affected Products

Nginx
Nginx-Ui