nginx-ui MCP Integration CVE-2026-33032: CVSS 9.8 Authentication Bypass Enables Full Server Takeover
The Hacker News·high signal
A critical authentication bypass in nginx-ui's MCP integration (codenamed MCPwn by Pluto Security) allows unauthenticated attackers to execute arbitrary commands on any nginx server running the MCP plugin. CVSS score of 9.8 reflects the zero-interaction attack path — no credentials needed, full server compromise. This is actively being exploited in the wild and represents the first confirmed weaponization of an MCP integration vulnerability.