PT-2026-108957 · Nginx-Ui · Nginx-Ui

CVE-2026-107808

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nginx UI versions 2.0.0 through 2.4.9
Description An authentication bypass exists where the POST /api/login endpoint checks EnabledOTP but fails to require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. This allows a session to be issued after password verification for passkey-only accounts, even if Enabled2FA indicates a second factor is active. An attacker with a valid password can bypass the registered passkey to gain administrative access.
Recommendations Update to version 2.5.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107808
GHSA-45GV-9WJV-XH7P

Affected Products

Nginx-Ui