High priorityDisclosed

Advisory · CVE-2026-102334

Nginx Proxy Manager login endpoints allow unlimited password guessing

Nginx Proxy Manager through 2.16.0 has no rate limiting on the login and 2FA endpoints, so unauthenticated attackers can brute-force credentials and TOTP codes to gain full administrative control.

Vendor
NginxProxyManager
Product
nginx-proxy-manager
Identifier / CWE
CVE-2026-102334
CWE-307
Action timing
Immediate
ELI5

Explain it like I’m five

The login door has no bouncer counting attempts. An attacker can try passwords as fast as the network allows until one works, and then keep guessing the two-factor code the same way.

SIMPLIFIED_ATTACK_PATH03 STEPS
  1. 01Unlimited password guesses

    An unauthenticated attacker sends repeated POST requests to /api/tokens with different passwords for a target account.

  2. 02Unlimited 2FA guesses

    Once a password succeeds, the attacker repeats the same against POST /api/tokens/2fa to guess the TOTP code.

  3. 03Full session access

    Successful guesses yield a valid session, giving the attacker administrative control over the proxy manager.

What happened

Nginx Proxy Manager through 2.16.0 lacks rate limiting on its authentication endpoints. Unauthenticated attackers can make unlimited password guesses against any account via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control. The weakness is improper restriction of excessive authentication attempts, and an upstream fix has been proposed in the project’s pull request #5908.

What to do

  1. Inventory Nginx Proxy Manager instances, especially any exposed to the internet.
  2. Upgrade to a release newer than 2.16.0 that includes the upstream rate-limiting fix.
  3. Restrict network access to the admin interface to trusted networks while remediation is underway.
  4. Review access logs for unusual volumes of requests to /api/tokens and /api/tokens/2fa, particularly from single sources.
  5. Enforce strong, unique passwords and, where available, place the admin interface behind an additional authentication layer.
  6. Rotate credentials if brute-forcing activity or successful logins from unexpected sources cannot be excluded.

Management note

This is a credential-guessing weakness in infrastructure that manages TLS termination and routing for everything behind it. The fix is straightforward, but exposure matters most here: anything internet-facing should be restricted immediately, then patched.