8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that userβs access, so an attacker who already stole a JWT can continue reading and modifying protected resources after the account is marked disabled. Since tokens can be used to create new accounts, it is possible the disabled user to maintain the privilege. Version 2.3.4 patches the issue.
AI Analysis
Disabled users can retain full API access through previously issued bearer tokens
Basic Information
ID
CVE-2026-33031
Source
GitHub_M
Published
Apr 20, 2026 at 20:12
Affected Product
Vendor
0xJacky
Product
nginx-ui
Version
< 2.3.4
Affected Versions
0xJacky nginx-ui < 2.3.4
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
0xJacky
Product
nginx-ui
Version
< 2.3.4