Detects Nginx UI instances where the /mcp_message endpoint is accessible without authentication. The MCP integration only applies IP whitelisting (empty by default = allow all) but no auth middleware on the message endpoint. An attacker can invoke MCP tools to restart nginx, create or modify config files, and reload the service — achieving complete control over the web server routing and traffic.
Is your app exploitable through CVE-2026-33032?
Scan your domain free