Nginxui is a web-based management interface for the widely deployed Nginx web server, presenting a critical control-plane role in many infrastructure environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in a narrow product surface centered on the Nginxui management application itself. The recurring weakness classes—missing authentication for critical functions, path traversal, exposure of sensitive information, improper access control, and input-validation gaps—reflect the high-value target that a management console represents and the inherent risks of exposing configuration and system state through a web interface. These flaws are particularly consequential because successful exploitation can grant attackers direct control over the Nginx instances they manage, affecting downstream services and data flows. Public exploit code has a moderate tendency to emerge for vulnerabilities in this product class; defenders should treat Nginxui instances as sensitive infrastructure and restrict access accordingly. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nginxui over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33032CRITICAL Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and / | Mar 30, 2026 | 9.8 | 75 | NO | YES |
CVE-2026-27944CRITICAL Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys r | Mar 5, 2026 | 9.8 | 63 | NO | YES |
CVE-2024-49368CRITICAL Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it t | Oct 21, 2024 | 9.8 | 40 | NO | NO |
CVE-2026-42238CRITICAL Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated | May 4, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-42222CRITICAL Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed | May 4, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-42221CRITICAL Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator accou | May 4, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-44015CRITICAL Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node poi | May 12, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-33026CRITICAL Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives a | Mar 30, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-33030CRITICAL Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any a | Mar 30, 2026 | 9.9 | 32 | NO | NO |
CVE-2026-34403HIGH Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin uncondition | Apr 20, 2026 | 8.1 | 31 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nginxui.
Media articles that mention a CVE ID that affects a product developed by Nginxui — matched by CVE ID, not by vendor name.