Improper validation of integrity check value in nginx-ui - CVE-2026-33026

 

Improper validation of integrity check value in nginx-ui - CVE-2026-33026

Published: April 23, 2026


Vulnerability identifier: #VU126939
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33026
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the host.

The vulnerability exists due to improper validation of integrity check values in the backup restore mechanism when processing a tampered encrypted backup archive. A remote privileged user can upload a crafted backup and inject malicious configuration to execute arbitrary commands on the host.

Exploitation requires access to the backup security token so the backup contents and integrity metadata can be modified and re-encrypted.


Affected software

nginx-ui

How to mitigate CVE-2026-33026

Install security update from vendor's website.

nginx-ui - update to 2.3.4

External References

Related Security Bulletins