CVE-2026-33026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

Scoring

Severity
CRITICAL
CVSS base score
9.4
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS probability
0.33%
CWE
CWE-312, CWE-347, CWE-354
Published
2026-03-30
Last modified
2026-03-31

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs