PT-2026-29103 · Nginx-Ui · Nginx-Ui

Dapickle

·

Published

2026-03-17

·

Updated

2026-04-07

·

CVE-2026-33026

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.4
Description Nginx UI, a web user interface for the Nginx web server, contains a flaw in its backup restore mechanism. Prior to version 2.3.4, attackers can manipulate encrypted backup archives and inject malicious configuration during the restoration process. The backup format lacks a trusted integrity root, relying on encryption keys provided to the client for both encryption and integrity verification. This creates a circular trust model where attackers can decrypt, modify, re-hash, and re-encrypt backups, effectively bypassing integrity checks. Successful exploitation could lead to persistent configuration tampering, backdoor insertion, and potentially arbitrary command execution on the host system. The issue stems from a cryptographic design weakness that remained exploitable even after a previous fix addressing unauthorized access to backup files. The vulnerability is related to the following files: backup crypto.go, backup.go, restore.go, and SystemRestoreContent.vue.
Recommendations Update Nginx UI to version 2.3.4 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06993
CVE-2026-33026
GHSA-FHH2-GG7W-GWPQ
GO-2026-4903
SUSE-SU-2026:1205-1

Affected Products

Nginx-Ui