{"id":"CVE-2026-102334","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-102334","summary":"Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers…","details":"Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.","published":"2026-09-28T23:17:01.837","modified":"2026-09-28T23:17:01.837","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908","label":"NginxProxyManager/nginx-proxy-manager#5908"},"references":[{"type":"WEB","url":"https://github.com/NginxProxyManager/nginx-proxy-manager"},{"type":"WEB","url":"https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58"},{"type":"WEB","url":"https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240"},{"type":"WEB","url":"https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182"},{"type":"WEB","url":"https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-28T23:17:01.837"}}