Critical nginx-ui MCP Authentication Bypass Exploited
🔒 A critical authentication bypass in nginx-ui (CVE-2026-33032, CVSS 9.8) is being actively exploited in the wild, allowing a single unauthenticated API request to take full control of exposed servers. The flaw stems from a missing authentication check on the /mcp_message endpoint while the companion /mcp endpoint retained middleware, exposing 12 MCP tools—seven of which enable destructive actions such as injecting configs, reloading services and intercepting traffic. Maintainers issued a fix in v2.3.4 the day after disclosure; organisations should update immediately, disable MCP if they cannot patch, restrict access to management interfaces and review logs and configurations for unauthorized changes.
