1 post
CVE-2026-33032 (CVSS 9.8, CWE-306) is an nginx-ui auth bypass rooted in route asymmetry: /mcp_message lacks AuthRequired and fails open on an empty…