CVE-2026-33032 Analysis: nginx-ui MCP Auth Bypass


How This Was Researched

This analysis of CVE-2026-33032 is based on the official GitHub security advisory by maintainer 0xJacky, the NVD entry, and technical reports from Pluto Security, Rapid7, and Recorded Future. Our methodology involved synthesizing these verified sources and reviewing public exposure data from Shodan. We did not conduct hands-on exploit testing or perform a full source-code audit beyond the specific code paths cited by the finders.

What Is CVE-2026-33032?

CVE-2026-33032 is a critical authentication bypass vulnerability in the nginx-ui web-based management tool, rated CVSS 9.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and classified as CWE-306: Missing Authentication for Critical Function. According to the official nginx-ui security advisory, versions at or below 2.3.3 are affected, while the NVD entry for CVE-2026-33032 lists versions <= 2.3.5; the flaw is fixed in v2.3.4, with the current latest version being v2.5.10. The vulnerability impacts a significant deployment footprint — over 430,000 Docker pulls and 11.4K GitHub stars — with an estimated 2,689 publicly exposed instances identified through Shodan favicon-hash searches.

What Is the nginx-ui MCP Authentication Bypass Vulnerability?

The nginx-ui MCP authentication bypass allows an attacker to execute arbitrary management commands without credentials by directly accessing the Model Context Protocol (MCP) message endpoint. The root cause is an asymmetry in route registration within mcp/router.go: the /mcp endpoint includes AuthRequired() middleware, but the /mcp_message endpoint, which handles the actual tool calls, does not. This critical endpoint also uses a fail-open IP whitelist that defaults to empty, effectively allowing all traffic. Exploitation requires only two unauthenticated HTTP requests: a GET to /mcp to initialize an SSE stream and obtain a session ID, followed by a POST to /mcp_message with a JSON-RPC 2.0 tools/call payload. Our CVE deep-dive archive has more cases of missing authentication.

Why Bolting MCP onto Existing Software Creates Authentication Gaps

This vulnerability exemplifies a systemic risk in rapidly integrating AI tool-calling frameworks like MCP onto existing applications without rigorously inheriting the parent application’s security model. The exposed MCP layer in nginx-ui presents 12 tools, seven of which are write or destructive operations like nginx_config_add, which can write a configuration file and trigger a reload in a single call. This creates a direct impact chain for attackers: from complete config injection and traffic interception (e.g., logging HTTP Authorization headers) to credential harvesting and full server takeover. For security teams evaluating MCP or other agentic integrations, this incident sets a clear due-diligence bar: audit every MCP endpoint’s authentication independently rather than assuming the parent application’s middleware applies; require allowlists to fail closed, so an empty list denies all traffic instead of permitting it; and treat any tool-calling endpoint that can write files or restart services as a critical function deserving the same review rigor as the admin console itself. As we saw in our pgAdmin 4 CVE analysis and our N-able N-central CVE deep-dive, new integration points often become the weakest link.

Active Exploitation and the CVE-2026-27944 Chain

CVE-2026-33032 is confirmed to be actively exploited in the wild, with reports from Recorded Future Insikt Group (Risk Score 94/100), PurpleOps, and Rapid7’s Emergent Threat Response in March and April 2026. Attackers frequently chain it with CVE-2026-27944, an unauthenticated backup download flaw that leaks an AES-256 key and IV, allowing decryption of backups containing user credentials, session tokens, and SSL private keys. This combination grants attackers complete control from initial access to data exfiltration. The disclosure-to-exploitation timeline was tight: Pluto Security’s Yotam Perkal reported the flaw on March 4, 2026, the fix commit landed March 14, v2.3.4 shipped March 15, the GHSA advisory followed March 27-28, the CVE was published March 30, and in-the-wild exploitation was confirmed by mid-April. While actively exploited and listed in the VulnCheck KEV, it is important to note that CVE-2026-33032 is not listed in the CISA Known Exploited Vulnerabilities catalog as of August 22, 2026.

Detection and Mitigation

Detecting exploitation involves monitoring access logs for POST requests to /mcp_message containing JSON-RPC bodies with tools/call, alongside signs of unexpected configuration changes or unplanned nginx reloads and restarts. File-integrity monitoring on nginx configuration directories is also recommended, and Rapid7 shipped scanner checks for this CVE on April 17, 2026. The definitive mitigation is an upgrade; use this checklist to prioritize remediation and hardening:

  • Upgrade to v2.3.4 or later. The fix shipped on March 15, 2026; v2.5.10 (released 2026-08-21) is the current release and the strongest option.
  • Set a non-empty IP whitelist for the MCP endpoints. The whitelist fails open when empty — an explicitly configured entry is required for filtering to take effect.
  • Restrict port 9000, nginx-ui’s default management port, via firewall rules, a VPN, or an authenticating reverse proxy.
  • Disable the MCP functionality entirely if it is unused in your environment.
  • Maintain detection coverage: keep file-integrity monitoring active on nginx configuration directories and alert on any POST to /mcp_message.

FAQ

Is CVE-2026-33032 listed in the CISA Known Exploited Vulnerabilities catalog?

No, as of August 22, 2026, CVE-2026-33032 is not listed in the CISA KEV catalog. However, it is confirmed as actively exploited in the wild by multiple security vendors like Rapid7 and Recorded Future, and it is included in VulnCheck’s KEV list.

Which nginx-ui versions are affected by the MCP authentication bypass?

According to the original finder Pluto Security, versions at or below 2.3.3 are vulnerable, with a fix released in v2.3.4. The NVD record lists versions <= 2.3.5 as affected. The latest version, v2.5.10, is not vulnerable.

Can I disable the MCP endpoint in nginx-ui without upgrading?

Yes, you can mitigate the risk by not using the MCP feature and, crucially, by setting a non-empty IP whitelist for the management interface. This prevents the fail-open condition. However, upgrading to a patched version (v2.3.4+) remains the only way to fully resolve the authentication flaw in the code.

  • NiteAgent — AI agent development, frameworks, and production patterns
  • Hermes Tutorials — Hermes Agent setup, configuration, and advanced workflows
  • ToolBrain — tool reviews, LLM comparisons, and AI workflow guides

Cross-links automatically generated from None.