CVE-2026-27944: exploitation status and patch state
CVE-2026-27944 · CVSS 9.8 CRITICAL · EPSS 22%
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.
Is CVE-2026-27944 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 22%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-27944
PlainSec has not published a story about this CVE.