Skip to content

Known CVE

Nginx UI < 2.3.3 - Information Disclosure

Nginx UI < 2.3.3 contains an information disclosure vulnerability caused by unauthenticated access to /api/backup endpoint exposing encryption keys in X-Backup-Security header, letting unauthenticated attackers download and decrypt full system backups.

CVE-2026-27944

Critical2026CVSS 9.8CWE-306

cve2026 · nginx-ui · unauth · exposure · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website