CVE-2026-33032 Detail
Description
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. At time of publication, there are no publicly available patches.
Metrics
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
CVSS 2.0 Severity and Vector Strings:
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf | CISA-ADP, GitHub, Inc. | Exploit Mitigation Vendor Advisory |
| https://websec.net/blog/cve-2026-33032-unauthenticated-nginx-ui-mcp-takeover-69e1200f9fceb1f3fbe9c47f | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | GitHub, Inc. |
Known Affected Software Configurations Switch to CPE 2.2
CPEs loading, please wait.
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
4 change records found show changes
CVE Modified by CVE 4/16/2026 6:16:37 PM
| Action | Type | Old Value | New Value |
|---|---|---|---|
| Added | Reference |
https://websec.net/blog/cve-2026-33032-unauthenticated-nginx-ui-mcp-takeover-69e1200f9fceb1f3fbe9c47f |
Initial Analysis by NIST 4/01/2026 2:19:13 PM
| Action | Type | Old Value | New Value |
|---|---|---|---|
| Added | CPE Configuration |
OR
*cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* versions up to (including) 2.3.5
|
|
| Added | Reference Type |
CISA-ADP: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf Types: Exploit, Mitigation, Vendor Advisory |
|
| Added | Reference Type |
GitHub, Inc.: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf Types: Exploit, Mitigation, Vendor Advisory |
CVE Modified by CISA-ADP 3/30/2026 3:16:25 PM
| Action | Type | Old Value | New Value |
|---|---|---|---|
| Added | Reference |
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf |
New CVE Received from GitHub, Inc. 3/30/2026 2:16:19 PM
| Action | Type | Old Value | New Value |
|---|---|---|---|
| Added | Description |
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. At time of publication, there are no publicly available patches. |
|
| Added | CVSS V3.1 |
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
| Added | CWE |
CWE-306 |
|
| Added | Reference |
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf |
Quick Info
CVE Dictionary Entry:
CVE-2026-33032
NVD
Published Date:
03/30/2026
NVD
Last Modified:
04/16/2026
Source:
GitHub, Inc.