CVE-2026-33032 is a critical authentication bypass vulnerability affecting Nginx UI versions 2.3.5 and prior. This flaw allows any network attacker to access the /mcp_message endpoint due to an empty default IP whitelist, bypassing authentication and enabling the invocation of Model Context Protocol (MCP) tools. Exploitation grants attackers complete Nginx service takeover, including the ability to restart Nginx, manipulate configuration files, and trigger reloads, resulting in a CVSS score of 9.8 Critical. While no public exploits or active exploitation have been reported, the vulnerability has garnered some community discussion, and no patches are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.5CPE matchmatch criteria | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.