Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3. | |
| Title | Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure | |
| Weaknesses | CWE-306 CWE-311 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-05T16:28:13.988Z
Updated: 2026-03-05T16:28:13.988Z
Reserved: 2026-02-25T03:11:36.690Z
Link: CVE-2026-27944
No data.
Status : Awaiting Analysis
Published: 2026-03-05T19:16:05.840
Modified: 2026-03-05T19:38:33.877
Link: CVE-2026-27944
No data.