A recently disclosed vulnerability in the Nginx UI has raised serious security concerns, as researchers confirmed that attackers can download and decrypt server backups without authentication. The vulnerability, which has a CVSS score of 9.8, poses a significant risk to organizations that expose the Nginx UI management environment to the internet.
See also: WordPress: Vulnerability in the User Registration & Membership plugin

Security researchers attribute the problem primarily to a lack of authentication, as well as improper handling of encrypted data. When exploited, the vulnerability allows unauthenticated attackers to retrieve sensitive backup files and decrypt them immediately, potentially revealing configuration files, credentials, session tokens private keys SSL.
According to the official announcement, the vulnerability stems from the /api/backup endpoint in the Nginx UI, which is accessible without authentication checks. The advisory explains: “/api/backup is accessible without authentication and exposes the encryption keys required to decrypt the backup in the X-Backup-Security response header.”
See also: CISA: Hikvision and Rockwell Automation vulnerabilities in the KEV Catalog
Due to this design flaw, attackers can request a full backup system and obtain the data directly from the server.
Although the backup files are encrypted, the encryption keys are exposed within the HTTP response itself. The vulnerability affects all versions of Nginx UI prior to 2.3.2, while version 2.3.3 contains a fix that addresses the issue.
Sensitive data is exposed in Nginx UI backups
Ένα παραβιασμένο αντίγραφο ασφαλείας του Nginx UI περιέχει μεγάλο όγκο ευαίσθητων επιχειρησιακών πληροφοριών. Το αρχείο περιλαμβάνει πολλαπλά κρυπτογραφημένα αρχεία που αποθηκεύουν βασικά δεδομένα διακομιστή.

Because the vulnerability exposes both encrypted files and keys, attackers can easily decrypt these files and gain a complete view of the target server's environment.
See also: OpenClaw AI Assistant: New cybersecurity threats from autonomous AI
This open source tool is not a standard component of NGINX and is not installed by default. However, many administrators prefer to use a web dashboard rather than editing configuration files directly.
Attackers can only exploit NGINX UI endpoints that are exposed to the public internet. It is best practice to restrict management interfaces to internal networks only.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
