CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107808

HIGHCVSS 8.1NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verificatio

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107808 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107808

HIGHCVSS 8.1NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verificatio

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]