Improper Authentication in nginx-ui - #VU142593
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass two-factor authentication and gain full administrative access.
The vulnerability exists due to improper authentication in the password login endpoint and secure session enforcement when processing password-based login requests for passkey-only accounts. A remote attacker can authenticate with a compromised password without being required to complete a passkey assertion to bypass two-factor authentication and gain full administrative access.
Only accounts configured with a registered passkey and no TOTP secret are affected. The issue also impacts step-up checks for sensitive actions.