GITHUBEXPLOIT 9.8 CRITICAL

Exploit for Missing Authentication for Critical Function in Nginxui Nginx_Ui_9E899FF8-ADEC-5A3D-B90C-1658DF69CA4D

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

CVE-2026-33032 / MCPwn Non-destructive detection tooling for the nginx-ui MCP authentication bypass known publicly as MCPwn. Ship a two-HTTP-request unauthenticated takeover of any nginx-ui instance running a vulnerable version. Table of Contents 1...
Visit Original Source

Basic Information

ID 9E899FF8-ADEC-5A3D-B90C-1658DF69CA4D
Published Apr 18, 2026 at 11:48
Modified Apr 18, 2026 at 11:49

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.