CVE-2026-61628

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-22: 309-22
Referenced assets2 URLs
Full discourse3 posts
  • abraxas@abraxas_null

    nginx-ignition exploit! unauthorized admin account creation. SSL cert creation, virtual host take-over ... all sorts of stuff. exploit: https://github.com/abraxas/CVE-2026-61628 lab write-up: https://abraxaslabs.tech/research/CVE-2026-61628

    02050124
    72 followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 nginx-ignition'da CVE-2026-61628 | CVSS 8.1 Yüksek seviyeli güvenlik açığı! nginx-ignition < 2.41.1 sürümlerinde, onboarding aşamasındaki sistemlerde bulunan race condition açığı, kimlik doğrulaması olmadan tam yetkili yönetici hesabı oluşturulmasına izin veriyor. Çözüm: 2.41.1+ sürümüne güncellemek.

    11121974
    2.3K followersView on X
  • abraxas@abraxas_null

    @ridvanyagli This is a good one! Exploit: https://github.com/abraxas/CVE-2026-61628 Lab Write-up: https://abraxaslabs.tech/research/CVE-2026-61628

    0000059
    72 followersView on X

Explore more