CVE-2026-107808 PUBLISHED

Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)

Assigner: GitHub_M
Reserved: 08.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor 0xJacky
Product nginx-ui
Versions
  • Version >= 2.0.0, < 2.5.0 is affected

References

Problem Types

  • CWE-287: Improper Authentication CWE
  • CWE-305: Authentication Bypass by Primary Weakness CWE
  • CWE-308: Use of Single-factor Authentication CWE