Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/keraattin/cve-2026-33032
ReconnaissanceVulnerability ScannersExploitationWeb SecurityNetwork SecurityPenetration TestingAPI Security
GitHubkeraattin/cve-2026-33032

CVE-2026-33032

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

View Repository
5445 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-33032 / MCPwn

CVE CVSS Status Affected License Python

Non-destructive detection tooling for the nginx-ui MCP authentication bypass known publicly as MCPwn. Ship a two-HTTP-request unauthenticated takeover of any nginx-ui instance running a vulnerable version.

Table of Contents

  1. Quick Facts
  2. Vulnerability Overview
  3. Technical Deep Dive
  4. Detection Strategy
  5. Installation
  6. Usage
  7. Example Output
  8. Chain with CVE-2026-27944
  9. Remediation
  10. Responsible Use
  11. References
  12. License

Quick Facts

FieldValue
CVE IDCVE-2026-33032
AliasMCPwn
CVSS 3.19.8 / Critical (AV:N / AC:L / PR:N / UI:N / S:U / C:H/I:H/A:H)
CWECWE-306 Missing Authentication for Critical Function
Affected productnginx-ui (github.com/0xjacky/nginx-ui)
Affected versionsAll versions prior to 2.3.4
Fixed version2.3.4
Exploitation statusActive in the wild (Picus Security, Recorded Future)
Shodan exposure~2,689 internet-facing instances
Publication date2026-04-15

Vulnerability Overview

nginx-ui exposes a Model Context Protocol (MCP) interface that lets an authenticated operator drive destructive tools such as nginx configuration edits, restart commands and backup operations through JSON-RPC.

The /mcp endpoint is guarded by the AuthRequired() middleware, while its paired /mcp_message endpoint, which actually receives the tool invocations, was deployed without the middleware. Any client who can reach the UI over the network can:

  1. Open a Server Sent Events (SSE) stream to /mcp and receive a fresh sessionID without presenting any credential.
  2. Use that sessionID to invoke any registered MCP tool by POSTing to /mcp_message, still unauthenticated.

The attacker gains complete control of the nginx process: edit server blocks to redirect traffic, extract TLS private keys via path reads, reload or stop nginx, and implant persistent backdoors.

Technical Deep Dive

Code-level root cause

// vulnerable (pre-2.3.4)
r.GET("/mcp",          AuthRequired(), mcpHandler)
r.POST("/mcp_message", mcpMessageHandler)    // missing middleware

// fixed in 2.3.4
r.GET("/mcp",          AuthRequired(), mcpHandler)
r.POST("/mcp_message", AuthRequired(), mcpMessageHandler)

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

End-to-end attack sketch

  Attacker                              nginx-ui (<2.3.4)
     |   1) GET /mcp  (no auth)                |
     | -------------------------------------->  |
     |   2) event: endpoint data: /mcp_message?sessionID=XYZ
     | <--------------------------------------  |
     |   3) POST /mcp_message?sessionID=XYZ     |
     |      body: JSON-RPC call_tool "nginx_reload" or
     |             "edit_config {...}"          |
     | -------------------------------------->  |
     |   4) 200 OK; tool executed with full privileges
     | <--------------------------------------  |

Impact matrix

MCP toolEffect on nginx server
edit_configRewrite arbitrary server blocks, insert attacker upstream
reload_nginxApply attacker configuration without manual action
stop_nginxDenial of service
read_fileExfiltrate TLS private keys, credentials from mounted paths
create_certRe-issue TLS certificates under attacker control
list_backups / downloadPull entire nginx-ui backup including node_secret and hashes

Detection Strategy

This repository intentionally avoids any destructive action. The detector only uses read-only MCP methods (tools/list). The logic:

> Step 1  Fingerprint nginx-ui via
>         GET /               (HTML title, JS bundles)
>         GET /api/settings   (JSON referencing nginx-ui keys)
>         Extract version via header / body regex
> Step 2  Open SSE stream to /mcp
>         Parse the first sessionID from the "endpoint" event
> Step 3  POST /mcp_message?sessionID=<id>
>         Body: {"jsonrpc":"2.0","method":"tools/list","params":{}}
>         No Authorization header
> Step 4  Vulnerable if status 200 and body contains a tool manifest
>         Patched if status 401 / 403 / 404
>         Inconclusive otherwise

Why this is safe

The tools/list JSON-RPC method is read-only. It enumerates which tools the MCP server knows about but invokes none of them. The script refuses to POST any other method and never constructs payloads for destructive tools.

Installation

git clone https://github.com/your-org/CVE-2026-33032-detector.git
cd CVE-2026-33032-detector
python3 --version      # 3.9 or newer
# No third-party packages required.

For the Nmap NSE component, copy nginx-ui-mcpwn.nse into your local scripts directory and refresh the script database:

cp nginx-ui-mcpwn.nse /usr/share/nmap/scripts/
sudo nmap --script-updatedb

Usage

Python detector

# Single target
python3 detect_nginx_ui_mcpwn.py --target https://nginx-ui.internal

# Bulk scan from file
python3 detect_nginx_ui_mcpwn.py --targets targets.txt --workers 20

# JSON (NDJSON) output suited for piping to jq
python3 detect_nginx_ui_mcpwn.py --target 10.0.0.5:9000 --json | jq .

Command line reference:

FlagPurpose
--targetSingle URL or host[:port]
--targetsNewline separated target file
--timeoutHTTP timeout, default 10 seconds
--workersConcurrent workers for bulk scans, default 10
--verify-tlsEnforce TLS certificate verification (off by default)
--jsonEmit NDJSON, one record per target
--no-bannerSuppress the ASCII banner

Nmap NSE

nmap -p 80,443,9000 --script nginx-ui-mcpwn 10.0.0.0/24
nmap -p 443 --script nginx-ui-mcpwn --script-args "nginx-ui-mcpwn.timeout=8" host.example.com

Example Output

Human readable

Download Tool