rootpwn

medium · CVSS v3 4.2

CVE-2026-61630

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable…

Description

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.

Scores

Severity
medium
CVSS v2
4.6
CVSS v3
4.2
CVSS v4
EPSS

← All CVEs