<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:55:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02720</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02720</link>
      <description>bdu:2026-02720</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02720</guid>
    </item>
    <item>
      <title>EUVD-2026-276567</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276567</link>
      <description>EUVD-2026-276567</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276567</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27944</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27944</link>
      <description>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27944</guid>
    </item>
    <item>
      <title>GHSA-g9w5-qffc-6762 — Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9w5-qffc-6762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/api/backup` endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the `X-Backup-Security` response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately.&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| CWE | CWE-306: Missing Authentication for Critical Function + CWE-311: Missing Encryption of Sensitive Data |
| Affected File | `api/backup/router.go` |
| Affected Function | `CreateBackup` (lines 8-11 in router, implementation in `api/backup/backup.go:13-38`) |
| Secondary File | `internal/backup/backup.go` |
| CVSS 3.1 | 9.8 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability exists due to two critical security flaws:&lt;/p&gt;
&lt;p&gt;### 1. Missing Authentication on /api/backup Endpoint&lt;/p&gt;
&lt;p&gt;In `api/backup/router.go:9`, the backup endpoint is registered without any authentication middleware:&lt;/p&gt;
&lt;p&gt;```go
func InitRouter(r *gin.RouterGroup) {
	r.GET(&amp;#34;/backup&amp;#34;, CreateBackup)  // No authentication required
	r.POST(&amp;#34;/restore&amp;#34;, middleware.EncryptedForm(), RestoreBackup)  // Has middleware
}
```&lt;/p&gt;
&lt;p&gt;For comparison, the restore endpoint correctly uses middleware, while the backup endpoint is completely open.&lt;/p&gt;
&lt;p&gt;### 2. Encryption Keys Disclosed in HTTP Response Headers&lt;/p&gt;
&lt;p&gt;In `api/backup/backup.go:22-33`, the AES…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/api/backup` endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the `X-Backup-Security` response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately.&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| CWE | CWE-306: Missing Authentication for Critical Function + CWE-311: Missing Encryption of Sensitive Data |
| Affected File | `api/backup/router.go` |
| Affected Function | `CreateBackup` (lines 8-11 in router, implementation in `api/backup/backup.go:13-38`) |
| Secondary File | `internal/backup/backup.go` |
| CVSS 3.1 | 9.8 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability exists due to two critical security flaws:&lt;/p&gt;
&lt;p&gt;### 1. Missing Authentication on /api/backup Endpoint&lt;/p&gt;
&lt;p&gt;In `api/backup/router.go:9`, the backup endpoint is registered without any authentication middleware:&lt;/p&gt;
&lt;p&gt;```go
func InitRouter(r *gin.RouterGroup) {
	r.GET(&amp;#34;/backup&amp;#34;, CreateBackup)  // No authentication required
	r.POST(&amp;#34;/restore&amp;#34;, middleware.EncryptedForm(), RestoreBackup)  // Has middleware
}
```&lt;/p&gt;
&lt;p&gt;For comparison, the restore endpoint correctly uses middleware, while the backup endpoint is completely open.&lt;/p&gt;
&lt;p&gt;### 2. Encryption Keys Disclosed in HTTP Response Headers&lt;/p&gt;
&lt;p&gt;In `api/backup/backup.go:22-33`, the AES…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9w5-qffc-6762</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0712 — nginx-ui: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0712</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in nginx-ui ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so eine vollständige Systembackup mit sensiblen Daten offenzulegen und zu entschlüsseln.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in nginx-ui ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so eine vollständige Systembackup mit sensiblen Daten offenzulegen und zu entschlüsseln.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0712</guid>
    </item>
  </channel>
</rss>
