CVE-2026-33032: Nginx UI Missing MCP Authentication
2026-04-17T07:23:43Z•c5976a75bf19b6ed3e51f1bea23a46d1740ce162d153fbaaacbdc072a644916d
CVE-2026-33032authentication-bypasscriticalmcpmodel-context-protocolnginxnginx-uipatch-availablepluto-securityunauthenticated-accessyotam-perkal
What happened
CVE-2026-33032 is a critical (CVSS 9.8) missing-authentication vulnerability in Nginx UI that allows unauthenticated remote actors to access Model Context Protocol (MCP) endpoints. Exploitation can lead to full compromise of confidentiality, integrity, and availability — including reading/modifying Nginx configurations and managing SSL certificates. The bug was reported by Yotam Perkal / Pluto Security, patched on 2026-03-15, and publicly disclosed via advisories on 2026-03-30. Immediate patching or mitigation is recommended for affected deployments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- c5976a75bf19b6ed3e51f1bea23a46d1740ce162d153fbaaacbdc072a644916d
- Enrichment time
- 2026-04-17T07:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.