Threat

CVE-2026-33032 nginx-ui ≤ 2.3.3 - Unauthenticated MCP Authentication Bypass via Missing AuthRequired() Middleware on /mcp_message

Page published

Publication date unknown · First observed: 10 Oct 2026

Coverage timeline

10 Oct 2026safe.securityobserved

Single-source advisory — one report is available.

Why it matters

CVE-2026-33032 exposes an MCP tool endpoint to unauthenticated access, letting attackers abuse the agent/tool-calling interface of nginx-ui without credentials — a concrete example of MCP server misconfiguration becoming an exploitable entry point.

CVE-2026-33032 is an unauthenticated authentication bypass in nginx-ui versions ≤ 2.3.3, caused by a missing AuthRequired() middleware on the /mcp_message endpoint of its Model Context Protocol (MCP) interface. An unauthenticated attacker can reach the MCP message handler directly, bypassing access controls on the agent-facing tool endpoint.