CVE-2026-33026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 20:16

Updated : 2026-03-30 20:16


NVD link : CVE-2026-33026

Mitre link : CVE-2026-33026

CVE.ORG link : CVE-2026-33026


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-347

Improper Verification of Cryptographic Signature

CWE-354

Improper Validation of Integrity Check Value