CVE-2026-102334
Received Received - Intake

Authentication Bypass in Nginx Proxy Manager

Vulnerability report for CVE-2026-102334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulnCheck

Description

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nginx_proxy_manager nginx_proxy_manager 2.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nginx Proxy Manager through version 2.16.0 has no rate-limiting on its authentication endpoints. This allows attackers to make unlimited attempts to guess passwords for any account without restriction. They can brute-force login credentials by repeatedly sending requests to POST /api/tokens. Once they gain access, they can also guess TOTP codes via POST /api/tokens/2fa to fully compromise accounts and take over administrative control.

Detection Guidance

Monitor authentication endpoint traffic for excessive POST requests to /api/tokens or /api/tokens/2fa. Check logs for repeated failed login attempts or rapid TOTP code guesses.

Impact Analysis

If you use Nginx Proxy Manager version 2.16.0 or earlier, attackers could gain unauthorized access to your system by guessing passwords and TOTP codes. This could lead to data breaches, unauthorized administrative actions, or complete system takeover. The high CVSS score indicates a severe risk of compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Enable rate-limiting on authentication endpoints in Nginx Proxy Manager. Implement account lockout after failed attempts and enforce strong password policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart