CVE-2026-61630
Received
Received - Intake
Authentication Bypass via TOTP Reuse in nginx Ignition
Vulnerability report for CVE-2026-61630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-21
Last updated on: 2026-09-21
Assigner: GitHub, Inc.
Description
Description
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nginx | ignition | From 2.33.0 (inc) to 2.35.0 (inc) |
| nginx | ignition | 2.35.1 |
| lucasdillmann | nginx-ignition | From 2.33.0 (inc) to 2.35.0 (inc) |
| lucasdillmann | nginx-ignition | 2.35.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |