CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102334

HIGHCVSS 7.4NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102334 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102334

HIGHCVSS 7.4NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]