CVE-2026-107808
github.com/0xjacky/nginx-ui: Improper Authentication (CVE-2026-107808)
Description
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.9.10-0.20250517140552-daee3ac7ade1Metrics
Show all metrics
Weakness classes (CWE)
CWE-287Class
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
cwe.mitre.org →CWE-305Base
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
cwe.mitre.org →CWE-308Base
Use of Single-factor Authentication
The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.
cwe.mitre.org →
References & sources
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-45gv-9wjv-xh7px_refsource_CONFIRM
- https://github.com/0xJacky/nginx-ui/commit/95cd21b70814e5d9a48a359aa238aeea1ac97429x_refsource_MISC
- https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0x_refsource_MISC
- https://github.com/0xJacky/nginx-uipackage
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-09 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-45gv-9wjv-xh7p
- SSVC: {"id":"CVE-2026-107808","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-10-09 16:17 UTC· security-advisories@github.com
- Description: Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.
- CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-287
- CWE: CWE-305