PT-2026-96118 · Unknown · Nginx-Ignition

CVE-2026-61628

·

Published

2026-09-21

·

Updated

2026-09-28

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nginx ignition versions prior to 2.41.1
Description An issue exists where the POST /api/users/onboarding/finish endpoint is accessible to unauthenticated users and allows the creation of an account with full ReadWrite admin permissions. The handler implements a check-then-act (TOCTOU) pattern—Time-of-Check to Time-of-Use—between verifying if onboarding is completed and the actual user creation. Because this process lacks an atomic guard, a remote unauthenticated attacker can exploit the window during a fresh deployment or state reset to create an administrator account. Furthermore, sending concurrent requests can allow an attacker to create multiple admin accounts simultaneously through a race condition.
Recommendations Update to version 2.41.1.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61628
GHSA-PXCX-FV34-X9P5
GO-2026-6540

Affected Products

Nginx-Ignition