
🔴 Nginx UI, Authentication Bypass, #CVE-2026-107808 (High) -DC-Oct2026-3028 https://dailycve.com/nginx-ui-authentication-bypass-cve-2026-107808-high-dc-oct2026-3028/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 Nginx UI, Authentication Bypass, #CVE-2026-107808 (High) -DC-Oct2026-3028 https://dailycve.com/nginx-ui-authentication-bypass-cve-2026-107808-high-dc-oct2026-3028/