PT-2026-102396 · Unknown · Nginx Proxy Manager
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nginx Proxy Manager versions prior to 2.16.1
Description
Lack of rate-limiting on authentication endpoints allows unauthenticated attackers to perform unlimited password guessing against any account. Attackers can brute-force login credentials via the 'POST /api/tokens' endpoint and subsequently guess Time-based One-Time Password (TOTP) codes via the 'POST /api/tokens/2fa' endpoint to obtain full session access and administrative control.
Recommendations
Update Nginx Proxy Manager to a version newer than 2.16.0.
Restrict access to the 'POST /api/tokens' and 'POST /api/tokens/2fa' endpoints to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Proxy Manager