Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.3.4之前版本存在竞争条件问题漏洞,该漏洞源于存在竞争条件,由于缺乏同步机制和非原子文件写入,可能导致主配置文件损坏,引发持久性拒绝服务或远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33032 | 9.8 CRITICAL | Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover |
| CVE-2026-33030 | 8.8 HIGH | Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys |
| CVE-2026-33029 | Nginx UI: DoS via Negative Integer Input in Logrotate Interval | |
| CVE-2026-33026 | nginx-ui Backup Restore Allows Tampering with Encrypted Backups | |
| CVE-2026-33027 | Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Di |
No comments yet