A walkthrough of the HackTheBox machine 'Snapped', a Linux box running nginx with an Nginx UI admin panel. Initial access is gained by exploiting CVE-2026-27944, an unauthenticated backup download vulnerability in Nginx UI that leaks AES encryption keys via the X-Backup-Security response header. Decrypting the backup reveals a

30m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as jonathanShell as root

Sort: