Skip to content

Hide Navigation Hide TOC

nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2)

Detects CVE-2026-33032 (CVSS 9.8): nginx-ui exposes an MCP server endpoint that executes system commands — including nginx reload/restart, config writes, and raw shell commands — without requiring authentication. An unauthenticated network attacker can invoke MCP tool calls directly against the nginx-ui service and gain OS-level command execution on the host. Detection covers (a) tool call patterns invoking nginx management functions without an Authorization header present in the same exchange, (b) MCP config blocks pointing at nginx-ui endpoints with no auth fields, (c) payloads referencing the nginx_command_execute / nginx_reload MCP tool names, and (d) content describing the unauthenticated MCP surface of nginx-ui. CWE-306 (Missing Authentication for Critical Function), CWE-78 (OS Command Injection).

Cluster A Galaxy A Cluster B Galaxy B Level
nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2) Agent Threat Rules Valid Accounts - T1078 (b17a1a56-e99c-403c-8948-561df0cffe81) Attack Pattern 1
nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1
nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2) Agent Threat Rules AI Model Inference API Access (90a420d4-3f03-4800-86c0-223c4376804a) MITRE ATLAS Attack Pattern 1
nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2) Agent Threat Rules Exploit Public-Facing Application (47d73872-5336-44f7-81e3-d30bc7e039dd) MITRE ATLAS Attack Pattern 1
nginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032) - ATR-2026-00536 (1009af15-3da8-5cba-9d77-8d4cc554a7d2) Agent Threat Rules Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern 2