From 2a0b83e6e8c14ea89c9f64c9d3b95e27a1ac396e Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:23:23 +0530 Subject: [PATCH 1/6] Add FortiWeb authentication bypass vulnerability check Signed-off-by: Aarush --- docs/Modules.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/Modules.md b/docs/Modules.md index 3c66a26f2..5ec85db5b 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -151,6 +151,7 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke - '**exponent_cms_cve_2021_38751_vuln**' – check the target for Exponent CMS CVE-2021-38751 - '**f5_cve_2020_5902_vuln**' – check the target for F5 RCE CVE-2020-5902 vulnerability - '**forgerock_am_cve_2021_35464_vuln**' – check the target for ForgeRock AM CVE-2021-35464 +- '**fortiweb_auth_bypass_cve_2025_64446_vuln** - check for FortiWeb authentication bypass vulnerability - '**galera_webtemp_cve_2021_40960_vuln**' – check the target for Galera WebTemplate CVE-2021-40960 - '**grafana_cve_2021_43798_vuln**' – check the target for Grafana CVE-2021-43798 vulnerability - '**graphql_vuln**' – check the target for exposed GraphQL introspection endpoint From b1ffe4e499e1fb1f301286e19bdd423b8932ddf6 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:29:23 +0530 Subject: [PATCH 2/6] Remove FortiWeb auth bypass vulnerability entry Removed entry for FortiWeb authentication bypass vulnerability. Signed-off-by: Aarush --- docs/Modules.md | 1 - 1 file changed, 1 deletion(-) diff --git a/docs/Modules.md b/docs/Modules.md index 5ec85db5b..3c66a26f2 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -151,7 +151,6 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke - '**exponent_cms_cve_2021_38751_vuln**' – check the target for Exponent CMS CVE-2021-38751 - '**f5_cve_2020_5902_vuln**' – check the target for F5 RCE CVE-2020-5902 vulnerability - '**forgerock_am_cve_2021_35464_vuln**' – check the target for ForgeRock AM CVE-2021-35464 -- '**fortiweb_auth_bypass_cve_2025_64446_vuln** - check for FortiWeb authentication bypass vulnerability - '**galera_webtemp_cve_2021_40960_vuln**' – check the target for Galera WebTemplate CVE-2021-40960 - '**grafana_cve_2021_43798_vuln**' – check the target for Grafana CVE-2021-43798 vulnerability - '**graphql_vuln**' – check the target for exposed GraphQL introspection endpoint From 6db5ee7a84b8d3fe34529bfb5983aca0ceffc334 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:45:01 +0530 Subject: [PATCH 3/6] Fix vulnerability name in wp_plugin_cve_2021_38314.yaml Signed-off-by: Aarush --- nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml index 6b2c22f46..88df2b91a 100644 --- a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml +++ b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml @@ -1,5 +1,5 @@ info: - name: CVE_2021_39320_vuln + name: CVE_2021_39314_vuln author: OWASP Nettacker Team severity: 7 description: Sensitive Information Leakage - The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress From 6fd226a7ac69c0796a408ff136f2a1ea69398386 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:45:59 +0530 Subject: [PATCH 4/6] Rename CVE identifier from 39314 to 39320 Signed-off-by: Aarush --- nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml index 88df2b91a..6b2c22f46 100644 --- a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml +++ b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml @@ -1,5 +1,5 @@ info: - name: CVE_2021_39314_vuln + name: CVE_2021_39320_vuln author: OWASP Nettacker Team severity: 7 description: Sensitive Information Leakage - The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress From 0c9084dd2b4b88a22667e11019ca61e9c802bc04 Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Sat, 4 Jul 2026 22:24:05 +0800 Subject: [PATCH 5/6] new module added --- docs/Modules.md | 1 + .../modules/vuln/nginx_ui_cve_2026_33032.yaml | 79 +++++++++++++++++++ 2 files changed, 80 insertions(+) create mode 100644 nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml diff --git a/docs/Modules.md b/docs/Modules.md index a51e8d0ea..dd75606a5 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -221,6 +221,7 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke - '**msexchange_cve_2021_26855_vuln**' – check the target for MS Exchange SSRF CVE-2021-26855 - '**msexchange_cve_2021_34473_vuln**' – check the target for MS Exchange CVE-2021-34473 vulnerability - '**novnc_cve_2021_3654_vuln**' – check the target for noVNC CVE-2021-3654 vulnerability +- '**nginx_ui_cve_2026_33032_vuln**' – check unauthenticated MCP endpoint exposure vulnerability CVE-2026-33032 - '**omigod_cve_2021_38647_vuln**' – check the target for OMIGOD CVE-2021-38647 vulnerability - '**paloalto_globalprotect_cve_2025_0133_vuln**' – check the target for PaloAlto GlobalProtect CVE-2025-0133 XSS vulnerability - '**paloalto_panos_cve_2025_0108_vuln**' – check the target for PaloAlto PAN-OS CVE-2025-0108 vulnerability diff --git a/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml b/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml new file mode 100644 index 000000000..9bfc9cec7 --- /dev/null +++ b/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml @@ -0,0 +1,79 @@ +info: + name: nginx_ui_cve_2026_33032_vuln + author: Nettacker Team + severity: critical + description: | + Detects a Broken Access Control vulnerability in Nginx UI versions prior + to 2.3.4. The `/mcp_message` endpoint processes unauthenticated JSON-RPC + requests and returns a JSON-RPC error indicating a missing session ID + instead of rejecting the request with an authentication error. Successful + detection indicates the endpoint is reachable without authentication and + is likely vulnerable to CVE-2026-33032. + references: + - https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf + - https://github.com/0xJacky/nginx-ui/commit/413dc631 + - https://nvd.nist.gov/vuln/detail/CVE-2026-33032 + profiles: + - vuln + - http + - cve + - cve2026 + - nginx_ui + - mcp + - unauth + +payloads: + - library: http + steps: + - method: post + timeout: 5 + headers: + User-Agent: "{user_agent}" + Content-Type: "application/json" + ssl: false + allow_redirects: false + url: + nettacker_fuzzer: + input_format: "{{schema}}://{target}:{{ports}}/mcp_message" + prefix: "" + suffix: "" + interceptors: + data: + schema: + - "http" + - "https" + ports: + - 80 + - 443 + - 9000 + + data: | + {{ + "jsonrpc":"2.0", + "method":"initialize", + "params":{{ + "protocolVersion":"2024-11-05", + "capabilities":{{}}, + "clientInfo":{{ + "name":"nettacker", + "version":"1.0" + }} + }}, + "id":1 + }} + + response: + condition_type: and + conditions: + status_code: + regex: "400" + reverse: false + + headers: + Content-Type: + regex: "application/json" + reverse: false + + content: + regex: '(?s)(?=.*"jsonrpc":)(?=.*"message")(?=.*"id").*' + reverse: false \ No newline at end of file From e4372dc1ee4d9be9eee5857031cccd24431cdde6 Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Sat, 4 Jul 2026 22:27:06 +0800 Subject: [PATCH 6/6] fix severity --- nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml b/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml index 9bfc9cec7..a1a3d94c0 100644 --- a/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml +++ b/nettacker/modules/vuln/nginx_ui_cve_2026_33032.yaml @@ -1,7 +1,7 @@ info: name: nginx_ui_cve_2026_33032_vuln author: Nettacker Team - severity: critical + severity: 9.8 description: | Detects a Broken Access Control vulnerability in Nginx UI versions prior to 2.3.4. The `/mcp_message` endpoint processes unauthenticated JSON-RPC @@ -21,6 +21,7 @@ info: - nginx_ui - mcp - unauth + - critical_severity payloads: - library: http