Nginx UI Security Update Advisory (CVE-2026-27944)

Nginx UI Security Update Advisory (CVE-2026-27944)

Overview

 

Nginx UI has released a security update to address a vulnerability in our its products. Users of affected products are advised to update to the latest version.

 

 

Affected Products

 

CVE-2026-27944

 

Nginx UI version: less than 2.3.2

 

 

Resolved Vulnerabilities

 

Unauthenticated backup download and encryption key exposure vulnerability in the Nginx UI (CVE-2026-27944)

 

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest version of Vulnerability Patches.

 

CVE-2026-27944

 

Nginx UI version: 2.3.3

 

 

References

 

[1] Unauthenticated Backup Download with Encryption Key Disclosure
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762