Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34403

31
FAUCET Score

CVE-2026-34403 is a Cross-Site WebSocket Hijacking vulnerability in Nginx UI versions prior to 2.3.5, which stems from improper WebSocket origin validation combined with insecure authentication token storage. The vulnerability allows attackers to establish authenticated WebSocket connections to vulnerable Nginx UI instances by luring logged-in administrators to malicious webpages, since authentication tokens are stored in cookies without HttpOnly or SameSite protections. The flaw affects all WebSocket endpoints in the application, creating a significant attack surface. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring minimal complexity and user interaction. While confidentiality and integrity impacts are rated as high, there is no availability impact. The attack requires minimal attacker privileges and no special access, making it broadly exploitable against any organization running vulnerable Nginx UI instances with logged-in administrators. While CVE-2026-34403 is not currently listed in the Known Exploited Vulnerabilities catalog, it is flagged as active on vulnerability hotlists and warrants immediate attention. The relatively low EPSS score suggests limited current exploitation prevalence, though this does not diminish the severity given the ease of exploitation and potential for lateral movement or configuration tampering. Organizations should prioritize patching to version 2.3.5 or later immediately.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.5CPE matchmatch criteria
cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 6th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/0xJacky/Nginx-UIFixed in: 1.9.10-0.20260316053337-1a9cd29a3082
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-78mf-482w-62qjhigh

Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints

Apr 21, 2026

References

github.com / 0xJacky/nginx-ui/releases/tag/v2.3.5
ProductRelease Notes
github.com / 0xJacky/nginx-ui/security/advisories/GHSA-78mf-482w-62qj
ExploitMitigationVendor Advisory