CVE-2026-33030 is a critical Insecure Direct Object Reference (IDOR) vulnerability affecting Nginx UI versions 2.3.3 and prior, a web user interface for the Nginx web server. This flaw allows any authenticated user to access, modify, and delete resources belonging to other users due to a lack of user ownership verification. Rated 9.9 CRITICAL, the vulnerability has a low attack complexity and requires only low privileges (an authenticated user) to achieve complete compromise of confidentiality, integrity, and availability of other users' data and configurations across the network. While there are no publicly available exploits, KEV catalog entries, or patches at this time, the vulnerability has garnered minor community discussion on social media platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.3CPE matchmatch criteria | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.