Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.3.4之前版本存在安全漏洞,该漏洞源于配置不当处理URL编码的遍历序列,可能导致经过身份验证的用户删除整个/etc/nginx目录,造成部分拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33032 | 9.8 CRITICAL | Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover |
| CVE-2026-33030 | 8.8 HIGH | Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys |
| CVE-2026-33028 | Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse | |
| CVE-2026-33029 | Nginx UI: DoS via Negative Integer Input in Logrotate Interval | |
| CVE-2026-33026 | nginx-ui Backup Restore Allows Tampering with Encrypted Backups |
No comments yet