Advisory · CVE-2026-102334
Nginx Proxy Manager login endpoints allow unlimited password guessing
Nginx Proxy Manager through 2.16.0 has no rate limiting on the login and 2FA endpoints, so unauthenticated attackers can brute-force credentials and TOTP codes to gain full administrative control.
- Vendor
- NginxProxyManager
- Product
- nginx-proxy-manager
- Identifier / CWE
- CVE-2026-102334
CWE-307 - Action timing
- Immediate
Explain it like I’m five
The login door has no bouncer counting attempts. An attacker can try passwords as fast as the network allows until one works, and then keep guessing the two-factor code the same way.
- 01Unlimited password guesses
An unauthenticated attacker sends repeated POST requests to /api/tokens with different passwords for a target account.
- 02Unlimited 2FA guesses
Once a password succeeds, the attacker repeats the same against POST /api/tokens/2fa to guess the TOTP code.
- 03Full session access
Successful guesses yield a valid session, giving the attacker administrative control over the proxy manager.
What happened
Nginx Proxy Manager through 2.16.0 lacks rate limiting on its authentication endpoints. Unauthenticated attackers can make unlimited password guesses against any account via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control. The weakness is improper restriction of excessive authentication attempts, and an upstream fix has been proposed in the project’s pull request #5908.
What to do
- Inventory Nginx Proxy Manager instances, especially any exposed to the internet.
- Upgrade to a release newer than 2.16.0 that includes the upstream rate-limiting fix.
- Restrict network access to the admin interface to trusted networks while remediation is underway.
- Review access logs for unusual volumes of requests to /api/tokens and /api/tokens/2fa, particularly from single sources.
- Enforce strong, unique passwords and, where available, place the admin interface behind an additional authentication layer.
- Rotate credentials if brute-forcing activity or successful logins from unexpected sources cannot be excluded.
Management note
This is a credential-guessing weakness in infrastructure that manages TLS termination and routing for everything behind it. The fix is straightforward, but exposure matters most here: anything internet-facing should be restricted immediately, then patched.