PT-2026-96118 · Unknown · Nginx-Ignition
CVE-2026-61628
·
Published
2026-09-21
·
Updated
2026-09-28
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
nginx ignition versions prior to 2.41.1
Description
An issue exists where the
POST /api/users/onboarding/finish endpoint is accessible to unauthenticated users and allows the creation of an account with full ReadWrite admin permissions. The handler implements a check-then-act (TOCTOU) pattern—Time-of-Check to Time-of-Use—between verifying if onboarding is completed and the actual user creation. Because this process lacks an atomic guard, a remote unauthenticated attacker can exploit the window during a fresh deployment or state reset to create an administrator account. Furthermore, sending concurrent requests can allow an attacker to create multiple admin accounts simultaneously through a race condition.Recommendations
Update to version 2.41.1.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ignition