Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27944

63
FAUCET Score

CVE-2026-27944 is a critical vulnerability in Nginx UI versions prior to 2.3.3, allowing unauthenticated attackers to access the /api/backup endpoint. This flaw discloses encryption keys in the X-Backup-Security header, enabling the download and decryption of full system backups containing sensitive data like user credentials and SSL private keys. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with over 12 mentions and media coverage. Organizations using affected Nginx UI versions should immediately upgrade to version 2.3.3 to mitigate this severe risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.3CPE matchmatch criteria
cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
22.16%
Probability of exploitation in next 30 days
EPSS Percentile
97.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-27944 · Mar 8, 2026
This CVE's current EPSS score of 0.2216 is in the 94th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

gopatch availablevia ghsa
Product: github.com/0xJacky/Nginx-UIFixed in: 2.3.3
3cxvendor investigatingvia llm_extracted
amazonvendor investigatingvia llm_extracted
burp_suitevendor investigatingvia llm_extracted
entrustvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
moxavendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
qwikvendor investigatingvia llm_extracted

Vendor Advisories (12)

jitsillm-jitsi-aff067debe4fad48HIGH

Nginx UI Information Disclosure (CVE-2026-27944)

Mar 16, 2026
amazonllm-amazon-c95c7ff647311229HIGH

Nginx UI Information Disclosure (CVE-2026-27944)

Mar 16, 2026
leantimellm-leantime-4cc6b3d1dbd71427HIGH

Nginx UI Information Disclosure (CVE-2026-27944)

Mar 16, 2026
nutanixllm-nutanix-19a1bde0dc5b9b8bHIGH

Nginx UI Information Disclosure (CVE-2026-27944)

Mar 16, 2026
horillallm-horilla-1ba849b11b8b01dcHIGH

Nginx UI Information Disclosure (CVE-2026-27944)

Mar 16, 2026
goGHSA-g9w5-qffc-6762critical

Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
proxmoxllm-proxmox-a64fb132c1936450CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
moxallm-moxa-7c422f86dd3ccf40CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
3cxllm-3cx-70508541d0f9cd22CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
burp_suitellm-burp_suite-410782fa8885b1c4CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
qwikllm-qwik-e0a88c40b1e94b61CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026
entrustllm-entrust-f60293110fdd3837CRITICAL

Nginx UI - Unauthenticated Backup Download with Encryption Key Disclosure

Mar 5, 2026

References

github.com / 0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762
ExploitVendor Advisory