GHSA-g9w5-qffc-6762 · Severity: critical · Ecosystem: go — Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
Conclusion & alert: CVE-2026-27944 is rated High Exploit Risk (87.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 7.31%, 92th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.02% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 6.30% | 7.31% | +1.02% |
| 2 | 2026-05-21 | 6.07% | 6.30% | +0.22% |
| 3 | 2026-05-12 | — | 6.07% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-g9w5-qffc-6762 · Severity: critical · Ecosystem: go — Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
| URL | Tags |
|---|---|
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762 | Exploit Vendor Advisory |