CVE-2026-107808 - Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
CVE ID :CVE-2026-107808 Published : Oct. 9, 2026, 4:17 p.m. | 1 hour, 12 minutes ago Description :Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no...