Summary
| Vulnerability Name | Nginx UI Authentication Bypass via MCP Endpoint (CVE-2026-33032) |
| Released on | April 16, 2026 |
| Affected Component | Nginx UI |
| Affected Version | Nginx UI ≤ 2.3.5 |
| Vulnerability Type | Authentication bypass |
| Exploitation Condition | 1. User authentication: not required. 2. Preconditions: default configurations. 3. Trigger mode: remote. |
| Impact | Exploitation difficulty: medium. When combined with other vulnerabilities, it may lead to remote code execution. Severity: critical. This vulnerability may result in a server compromise. |
| Official Solution | Available |
About the Vulnerability
Component Introduction
Nginx UI is an open-source, web-based graphical management tool designed to fully simplify the configuration and management of Nginx servers through a visual interface. Built on the Vue framework by using the Go language, it enables complex operations that traditionally require command-line interaction to be completed within a web browser. These complex operations, for example, include managing virtual hosts, configuring reverse proxies, monitoring the server status (such as CPU and memory) in real time, and viewing logs online.
Vulnerability Description
On April 16, 2026, Sangfor FarSight Labs received notification of the authentication bypass vulnerability in Nginx UI (CVE-2026-33032), classified as critical in threat level.
Specifically, the /mcp_message endpoint of Nginx UI contains an authentication vulnerability. The endpoint only applies IP whitelisting, and the default IP whitelist is empty. Unauthorized attackers can exploit this endpoint to establish Model Context Protocol (MCP) sessions. When combined with CVE-2026-27944, attackers can retrieve the node_secret and execute arbitrary commands. This vulnerability has been observed being actively exploited in the wild.
Affected Versions
The following Nginx UI versions are affected:
Nginx UI ≤ 2.3.5
Solutions
Remediation Solutions
Official Solutions
The latest version has been officially released to fix the vulnerability. Affected users are advised to update Nginx UI to 2.3.6.
Download link: https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6
Temporary Solutions
- Disable unused functional modules to reduce attack entry points.
- Follow the principle of least privilege to strictly control the scope of permissions for sensitive operations.
- Do not expose services to the Internet unless necessary, to limit the access sources to trusted ranges.
- Regularly update the system and components to secure versions so that known vulnerabilities can be patched at the earliest opportunity.
Sangfor Solutions
Proactive Vulnerability Detection
The following Sangfor service can proactively detect CVE-2026-33032 vulnerabilities and quickly identify vulnerability risks in batches in business scenarios:
- Athena Extended Detection and Response (XDR): The corresponding detection solution will be released on April 19, 2026. The rule ID is SF-2026-00875.
Vulnerability Monitoring
The following Sangfor services support CVE-2026-33032 vulnerability monitoring, and can quickly identify affected assets and the impact scope in business scenarios in real time through traffic collection:
- Athena Network Detection and Response (NDR): The corresponding monitoring solution will be released on April 24, 2026. The rule ID is 11228014.
- Athena Managed Detection and Response (MDR): The corresponding monitoring solution will be released on April 24, 2026. The rule ID is 11228014. In this case, make sure that Athena MDR is integrated with Athena NDR.
- Athena Extended Detection and Response (XDR): The corresponding monitoring solution will be released on April 24, 2026. The rule ID is 11228014.
Vulnerability Prevention
The following Sangfor services can effectively block CVE-2026-33032 exploits:
- Athena Next-Generation Firewall (NGFW): The corresponding prevention solution will be released on April 24, 2026. The rule ID is 11228014.
- Sangfor Web Application Firewall (WAF): The corresponding prevention solution will be released on April 24, 2026. The rule ID is 11228014.
- Athena MDR: The corresponding prevention solution will be released on April 24, 2026. The rule ID is 11228014. In this case, make sure that Athena MDR is integrated with Athena NGFW.
- Athena XDR: The corresponding prevention solution will be released on April 24, 2026. The rule ID is 11228014. In this case, make sure that Athena XDR is integrated with Athena NGFW.
Timeline
On April 16, 2026, Sangfor FarSight Labs received notification of the authentication bypass vulnerability in Nginx UI (CVE-2026-33032).
On April 17, 2026, Sangfor FarSight Labs released a vulnerability alert.
Reference
https://github.com/advisories/GHSA-h6c2-x2m2-mwhf
Learn More
Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence. Sangfor FarSight Labs works with other security vendors and the security community at large to identify and verify global cyber threats, providing fast and easy protection for customers.