CVE-2026-33032 is a critical authentication bypass vulnerability in nginx-ui affecting versions 2.3.5 and earlier. The flaw is in the Model Context Protocol (MCP) integration, which exposes two HTTP endpoints used for MCP communication: one endpoint for establishing an MCP session and another for sending MCP tool invocations. In vulnerable versions, the session-establishment endpoint is protected by both IP allowlisting and authentication middleware, but the message-handling endpoint applies only IP allowlisting and omits the authentication check. Because the default IP allowlist is empty and is treated as allow-all, unauthenticated remote attackers can reach the message endpoint and invoke privileged MCP tools without valid credentials. Exposed MCP functionality includes reading nginx-related files, creating, modifying, and deleting nginx configuration files, and restarting or reloading nginx, enabling full administrative control over the managed nginx service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a self-contained Docker lab and Python exploit demonstrating a chained zero-credential compromise of nginx-ui. The main exploit is exploit/exploit.py, which performs two stages: first, it abuses unauthenticated GET /api/backup to download an encrypted backup and recover the AES key/IV from the X-Backup-Security header, then decrypts nginx-ui.zip and parses app.ini to extract the [node] Secret. Second, it uses that secret to open an SSE session on /mcp, recover a sessionId, and then invoke privileged MCP tools through unauthenticated POST /mcp_message requests. The intended post-exploitation action is nginx takeover by overwriting default.conf so traffic is proxied to http://malicious_site:80, followed by reload_nginx to make the change live immediately. A reset path restores proxying to http://webapp:80. Repository structure supports the demo: docker-compose.yml launches a vulnerable uozi/nginx-ui:v2.3.1 instance on ports 8080 and 9000, a legitimate webapp container, and a malicious phishing container. nginx-ui/app.ini contains the lab configuration, including an empty Node.IPWhiteList and a node secret. nginx/conf.d/default.conf is the initial legitimate reverse-proxy config. webapp/index.html is the benign login page, while malicious/index.html is a phishing clone with a client-side credential capture panel exposed via ?debug=1 for demonstration. Overall, this is a real exploit repository rather than a detector: it automates credential-less secret extraction, privileged MCP access, configuration overwrite, and live nginx reload to redirect victim traffic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
94 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated MCP endpoint vulnerability in Nginx UI referenced as matching the debug build's MCP-chain artifacts.
Critical missing-authentication vulnerability in nginx-ui's MCP endpoints that leaves /mcp_message accessible without authentication, enabling remote attackers to invoke privileged configuration-management functions and gain full control over nginx and proxied traffic.
An unauthenticated takeover vulnerability affecting Nginx UI MCP, referenced in a pull request/title context.
Referenced only as a related article about nginx-ui MCPwn; no substantive vulnerability details are provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.