CVE-2026-27944 – Unauthenticated backup download and encryption key disclosure in Nginx UI
CVE-2026-27944 is a critical information disclosure vulnerability in Nginx UI (the web user interface for managing Nginx). Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and returns an encryption key in the X-Backup-Security response header. An unauthenticated attacker can download a full system backup (which may include user credentials, session tokens, SSL private keys, and Nginx configuration files) and immediately decrypt it using the disclosed key. The issue has a CVSSv3.1 base score of 9.8 (Critical) and is fixed in Nginx UI 2.3.3.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:
