Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
0xjacky
0xjacky nginx-ui |
|
| Vendors & Products |
0xjacky
0xjacky nginx-ui |
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0. | |
| Title | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass) | |
| Weaknesses | CWE-287 CWE-305 CWE-308 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T15:11:44.387Z
Reserved: 2026-10-08T21:23:59.820Z
Link: CVE-2026-107808
No data.
Status : Awaiting Analysis
Published: 2026-10-09T16:17:25.237
Modified: 2026-10-09T16:38:57.820
Link: CVE-2026-107808
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:30:09Z