Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | nginx-ui δÊÚȨ±¸·ÝÏÂÔØÓë¼ÓÃÜÃÜԿй¶Îó²î |
CVE ID | CVE-2026-27944 |
Îó²îÀàÐÍ | δÊÚȨ»á¼û | ·¢Ã÷ʱ¼ä | 2026-3-9 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
nginx-uiÊÇÒ»¿îÓÃÓÚÖÎÀíNginxµÄ¿ªÔ´Web¿ÉÊÓ»¯ÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ìṩ»ùÓÚä¯ÀÀÆ÷µÄͼÐλ¯½çÃæ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÉèÖúÍά»¤NginxЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸ÃÏîĿ֧³ÖÕ¾µãÉèÖÃÖÎÀí¡¢Ö¤ÊéÖÎÀí¡¢ÈÕÖ¾Éó²é¡¢ÉèÖÃÎļþ±à¼¼°ÔÚÏßÖØÔØµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼ò»¯NginxµÄÔËάºÍÖÎÀíÁ÷³Ì¡£¡£¡£¡£¡£¡£nginx-uiͨ³£°²ÅÅÔÚЧÀÍÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýWeb¿ØÖÆÌ¨ÊµÏÖ¶ÔNginxÉèÖúÍÔËÐÐ״̬µÄ¼¯ÖÐÖÎÀí¡£¡£¡£¡£¡£¡£
2026Äê3ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬¿Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½nginx-uiδÊÚȨ±¸·ÝÏÂÔØÓë¼ÓÃÜÃÜԿй¶Îó²î¡£¡£¡£¡£¡£¡£ÓÉÓÚ/api/backup½Ó¿ÚδÉèÖÃÉí·ÝÈÏÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÎÞÐèµÇ¼µÄÇéÐÎÏÂÖ±½Ó»á¼û¸Ã½Ó¿Ú²¢ÏÂÔØÏµÍ³ÍêÕû±¸·ÝÎļþ¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬Ð§ÀÍÆ÷ÔÚÏìӦͷX-Backup-SecurityÖÐÒÔÃ÷ÎÄÐÎʽ·µ»ØÓÃÓÚ½âÃܱ¸·ÝµÄAES-256¼ÓÃÜÃÜÔ¿ºÍIV£¬£¬£¬£¬£¬£¬£¬µ¼Ö±¸·ÝÊý¾ÝµÄ¼ÓÃܱ£»£»£»¤Ê§Ð§¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÃÜÔ¿¶ÔÏÂÔØµÄ±¸·ÝÎļþ¾ÙÐнâÃÜ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Êý¾Ý¿âÐÅÏ¢¡¢Óû§Æ¾Ö¤¡¢»á»°ÁîÅÆ¡¢NginxÉèÖÃÎļþÒÔ¼°SSL˽ԿµÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ôì³ÉÑÏÖØÐÅϢй¶Σº¦£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄܽøÒ»²½Òý·¢ÕË»§½ÓÊÜ¡¢Ð§ÀÍαÔì»òϵͳÉèÖñ»ÀÄÓõÈÇå¾²Ó°Ïì¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
nginx-ui < 2.3.2
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/0xJacky/nginx-ui/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762/https://nvd.nist.gov/vuln/detail/CVE-2026-27944