CVE-2026-33026 impacts Nginx UI versions prior to 2.3.4, where a flaw in the backup restore mechanism allows authenticated attackers to tamper with encrypted backup archives and inject malicious configurations during restoration. This is a critical vulnerability (CVSS 9.1) that is remotely exploitable with low attack complexity, requiring high privileges but no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.4CPE matchmatch criteria | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.