CVE-2026-33026 Details
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.
A vulnerability in Nginx UI's backup restore mechanism prior to version 2.3.4 allows attackers to manipulate encrypted backup archives and inject harmful configuration during the restoration process. The issue arises because the backup format lacks a trusted integrity root, enabling modification of the encrypted contents without detection. In certain configurations, this could lead to arbitrary command execution on the host.
Users are advised to update to Nginx UI version 2.3.4, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-fhh2-gg7w-gwpq | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4 | [email protected] | ProductRelease Notes |
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-fhh2-gg7w-gwpq | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nginxui nginx ui | < 2.3.4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | New CVE Received | [email protected] |