#nginx-ui

1 post

Aug 22, 2026

CVE-2026-33032 Analysis: nginx-ui MCP Auth Bypass

CVE-2026-33032 (CVSS 9.8, CWE-306) is an nginx-ui auth bypass rooted in route asymmetry: /mcp_message lacks AuthRequired and fails open on an empty…