CVE-2026-33026CRITICAL 9.1EPSS p24.4%
CVE-2026-33026CVE-2026-33026
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.
Scoring
| CVSS 3.1 | 9.1 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.33% probability of exploitation · percentile 24.4% · 2026-06-18T12:00:27Z |
| Published | 2026-03-30 |
| Last modified | 2026-04-01 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Cleartext Storage of Sensitive Informationcwe-312 | 0% | live |
| Weakness | Improper Verification of Cryptographic Signaturecwe-347 | 0% | live |
| Weakness | Improper Validation of Integrity Check Valuecwe-354 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.