Nginx UI disclosed a critical vulnerability, CVE-2026-27944 (CVSS 9.8), that allows unauthenticated attackers to download and immediately decrypt full system backups from exposed management interfaces. The issue affects Nginx UI versions prior to 2.3.2 and is addressed by upgrading to 2.3.3+. The root cause is a combination of missing authentication on the /api/backup endpoint (CWE-306) and improper handling of cryptographic material (CWE-311), enabling direct access to backup archives.
Exploitation is straightforward: an attacker can send a GET request to /api/backup to retrieve an encrypted ZIP backup, while the server simultaneously leaks the Base64-encoded AES-256 key and IV in the X-Backup-Security HTTP response header, allowing immediate decryption. Reported exposed contents include database.db (user credentials), app.ini configuration, SSL certificates and private keys, Nginx configuration and virtual host data, and potentially session tokens, creating follow-on risk for console takeover, man-in-the-middle enablement, and broader network pivoting. A public PoC is available, increasing the likelihood of opportunistic exploitation; the primary mitigation is to upgrade to Nginx UI 2.3.3 or later and ensure the management interface is not publicly reachable.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Belgium's Centre for Cybersecurity issued an advisory warning that the missing-authentication flaw in Nginx UI could lead to full system compromise and urged immediate patching. The notice reflects official government-level dissemination of the risk to defenders.
Follow-on advisories and news coverage stated that affected Nginx UI versions should be upgraded to 2.3.3 or later and warned against exposing the management interface or backup endpoint to the public internet. Additional recommendations included VPN-only access, IP allowlisting, MFA, segmentation, and monitoring for unauthenticated GET requests to /api/backup.
runZero published asset-discovery guidance for CVE-2026-27944, including a query and favicon-based identification method to help defenders find potentially vulnerable Nginx UI instances. The guidance reiterated that versions prior to 2.3.3 were affected and urged organizations to upgrade.
A GitHub pull request to the projectdiscovery nuclei-templates repository added a detection template for identifying exposed Nginx UI /api/backup endpoints that leak backup decryption material in the X-Backup-Security header. The submission included logic to detect encrypted backup ZIP responses and extract the leaked key and IV.
A critical vulnerability, CVE-2026-27944, was disclosed in Nginx UI after researchers found the /api/backup endpoint could be accessed without authentication and exposed the AES-256 key and IV needed to decrypt downloaded backups. The flaw could let remote attackers obtain sensitive data including credentials, session tokens, SSL private keys, and configuration files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcecybersecuritynews.com
Open sourcerunzero.com
Open sourcegithub.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.