CVE-2026-107808
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Nginx UI via Passkey-Only Session

Vulnerability report for CVE-2026-107808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.0.0, < 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-305 The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
CWE-308 The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Nginx UI versions 2.0.0 to 2.5.0. When EnabledPasskey is true and no TOTP secret is configured, the login endpoint checks EnabledOTP but does not require a WebAuthn assertion. This allows attackers with a user's password to bypass 2FA and gain administrative access without the registered passkey.

Detection Guidance

Check if your nginx-ui version is between 2.0.0 and 2.5.0. Inspect login API responses for POST /api/login to see if passkey enforcement is missing when EnabledPasskey is true. Review access logs for unauthorized administrative actions or sessions without passkey verification.

Impact Analysis

An attacker who obtains a user's password can take over the account and reach administrative functionality without the registered passkey. This includes potential full system compromise via the terminal feature, as the 2FA enforcement is bypassed.

Compliance Impact

This vulnerability allows attackers to bypass multi-factor authentication (MFA) by exploiting a flaw where passkey-only accounts are treated as single-factor when EnabledPasskey is true. This undermines security controls required by GDPR and HIPAA, which mandate strong authentication for sensitive data access. Non-compliance risks include unauthorized data exposure and regulatory penalties.

Mitigation Strategies

Upgrade nginx-ui to version 2.5.0 or later immediately. After upgrading, replace node secrets and JWT secrets, rotate all downstream credentials, and review access logs for signs of unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart