Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nginxproxymanager nginx-proxy-manager
|
|
| Vendors & Products |
Nginxproxymanager nginx-proxy-manager
|
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control. | |
| Title | Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection | |
| First Time appeared |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:21:41.072Z
Reserved: 2026-09-28T22:08:55.547Z
Link: CVE-2026-102334
No data.
Status : Received
Published: 2026-09-28T23:17:01.837
Modified: 2026-09-28T23:17:01.837
Link: CVE-2026-102334
No data.
OpenCVE Enrichment
Updated: 2026-09-28T23:30:09Z
Weaknesses