Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107808

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Oct 09, 2026
Vendor unknown

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.

References