MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #11

High-severity flaw disclosed in Nginx UI login checks

Original: 🟠 CVE-2026-107808 - High (8.1) Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /

A new high-severity vulnerability, CVE-2026-107808 with a CVSS score of 8.1, has been disclosed in Nginx UI, the web management interface for the Nginx web server. Versions 2.0.0 through 2.5.0 fail to properly enforce passkey authentication: the login endpoint checks whether OTP is enabled but does not require a WebAuthn assertion when passkeys are enabled and no TOTP secret is configured, potentially allowing passkey-only accounts to bypass authentication. Security teams are urged to update to version 2.5.0 or later.

Why now: Administrators running Nginx UI are checking whether their versions are exposed and need to patch a serious authentication bypass.

Nginx UINginxCVE-2026-107808

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1649429