216.73.217.22

CVE-2026-27944

· Published 05/03/2026 20:16 · Modified 14/04/2026 11:20 · Author: The MITRE Corporation

Labels: CVE-2026-27944 2026-03-05CVE-2026-27944CWE-306[email protected]

Essential information

Published
05/03/2026 20:16
Modified
14/04/2026 11:20
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nginx / nginx ui cpe:2.3:a:nginx:nginx_ui:<2.3.3:*:*:*:*:*:*:*

References