CVE-2026-33032
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads achieving complete nginx service takeover. At time of publication, there are no publicly available patches.
5 articles across 5 outlets · first covered Apr 15, 2026 · latest Apr 15, 2026
Coverage timeline
-
nginx UI flaw lets attackers hijack NGINX via CVE-2026-33032www.darkreading.com · Apr 15, 2026
-
CVE-2026-33032: severe nginx-ui bug grants unauthenticated server accesssecurityaffairs.com · Apr 15, 2026
-
Nginx UI flaw CVE-2026-33032 exploited, allows server takeoverwww.securityweek.com · Apr 15, 2026
-
nginx UI flaw CVE-2026-33032 exploited, allowing server takeoverthehackernews.com · Apr 15, 2026
-
nginx-ui auth bypass CVE-2026-33032 lets attackers control serverswww.infosecurity-magazine.com · Apr 15, 2026