Skip to main content
CRITICAL

CVE-2026-27944

Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure

CVSS v3

9.8

CRITICAL

EPSS Score

5.8 %

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

Technical details

CVSS v3 Vector
3.1
Published
2026-03-05
Last Modified
2026-03-10

Frequently asked questions

What is CVE-2026-27944?

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

Is CVE-2026-27944 actively exploited?

A proof-of-concept exploit exists for CVE-2026-27944, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-27944?

CVE-2026-27944 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-27944 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key