CVE-2026-34403 is a Cross-Site WebSocket Hijacking vulnerability in Nginx UI versions prior to 2.3.5, which stems from improper WebSocket origin validation combined with insecure authentication token storage. The vulnerability allows attackers to establish authenticated WebSocket connections to vulnerable Nginx UI instances by luring logged-in administrators to malicious webpages, since authentication tokens are stored in cookies without HttpOnly or SameSite protections. The flaw affects all WebSocket endpoints in the application, creating a significant attack surface. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring minimal complexity and user interaction. While confidentiality and integrity impacts are rated as high, there is no availability impact. The attack requires minimal attacker privileges and no special access, making it broadly exploitable against any organization running vulnerable Nginx UI instances with logged-in administrators. While CVE-2026-34403 is not currently listed in the Known Exploited Vulnerabilities catalog, it is flagged as active on vulnerability hotlists and warrants immediate attention. The relatively low EPSS score suggests limited current exploitation prevalence, though this does not diminish the severity given the ease of exploitation and potential for lateral movement or configuration tampering. Organizations should prioritize patching to version 2.3.5 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.5CPE matchmatch criteria | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.