CVE 8.6 HIGH

Nginx-UI: Disabled users retain full API access through previously issued bearer tokens_CVE-2026-33031

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attacker who already stole a JWT can continue reading and modifying protected resources after the account is marked disabled. Since tokens can be used to create new accounts, it is possible the disabled user to maintain the privilege. Version 2.3.4 patches the issue.

AI Analysis

Disabled users can retain full API access through previously issued bearer tokens

Basic Information

ID CVE-2026-33031
Source GitHub_M
Published Apr 20, 2026 at 20:12

Affected Product

Vendor 0xJacky
Product nginx-ui
Version < 2.3.4
Affected Versions 0xJacky nginx-ui < 2.3.4

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor 0xJacky
Product nginx-ui
Version < 2.3.4

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.