Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
PoC: CVE-2026-27944
CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption
PoC: Cve-2026-27944-Tools-Exploit
Suka suka lah
PoC: CVE-2026-27944
An educational deep-dive into CVE-2026-27944
PoC: HTB-Snapped-Writeup
Writeup de la máquina Snapped (Hard) de Hack The Box. Foothold: CVE-2026-27944 — Nginx UI unauthenticated backup disclosure Privilege Escalation: CVE-2026-3888 — snapd race condition LPE Técnicas: subdomain enumeration, AES decryption, bcrypt cracking, namespace manipulation, dynamic linker hijacking.
PoC: HTB-Snapped-Writeup
HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race condition LPE) to achieve full system compromise.
PoC: CVE-2026-27944-poc
poc for CVE-2026-27944
PoC: CVE-2026-27944
Automated exploit script for CVE-2026-27944 (Nginx UI). Downloads/decrypts backups, extracts system secrets, and creates rogue admin accounts for full dashboard access.
PoC: -nginxui_discover
Nginx UI Discovery Scanner - CVE-2026-27944 Version Detector
PoC: CVE-2026-27944-Lab
Educational lab demonstrating CVE-2026-27944 - Unauthenticated Backup Download with Encryption Key Disclosure in Nginx-UI < 2.3.2. Includes vulnerable server, PoC exploit, and CTF flags.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free