CVE-2026-33032: Nginx UI Missing MCP Authentication

2026-04-17T07:23:43Zc5976a75bf19b6ed3e51f1bea23a46d1740ce162d153fbaaacbdc072a644916d
CVE-2026-33032authentication-bypasscriticalmcpmodel-context-protocolnginxnginx-uipatch-availablepluto-securityunauthenticated-accessyotam-perkal

What happened

CVE-2026-33032 is a critical (CVSS 9.8) missing-authentication vulnerability in Nginx UI that allows unauthenticated remote actors to access Model Context Protocol (MCP) endpoints. Exploitation can lead to full compromise of confidentiality, integrity, and availability — including reading/modifying Nginx configurations and managing SSL certificates. The bug was reported by Yotam Perkal / Pluto Security, patched on 2026-03-15, and publicly disclosed via advisories on 2026-03-30. Immediate patching or mitigation is recommended for affected deployments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
c5976a75bf19b6ed3e51f1bea23a46d1740ce162d153fbaaacbdc072a644916d
Enrichment time
2026-04-17T07:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.