PT-2026-102396 · Unknown · Nginx Proxy Manager

·

CVE-2026-102334

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nginx Proxy Manager versions prior to 2.16.1
Description Lack of rate-limiting on authentication endpoints allows unauthenticated attackers to perform unlimited password guessing against any account. Attackers can brute-force login credentials via the 'POST /api/tokens' endpoint and subsequently guess Time-based One-Time Password (TOTP) codes via the 'POST /api/tokens/2fa' endpoint to obtain full session access and administrative control.
Recommendations Update Nginx Proxy Manager to a version newer than 2.16.0. Restrict access to the 'POST /api/tokens' and 'POST /api/tokens/2fa' endpoints to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102334

Affected Products

Nginx Proxy Manager