← Back to search

CVE-2026-61630

4.2 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows any user with OTP 2FA enabled to reuse their TOTP during a 30-second window, potentially leading to unauthorized access.
Exploitability
Exploitation requires a user who has enabled OTP 2FA and can manipulate the timing of their authentication within the validity window; moderately difficult.
Blast radius
If exploited, this could result in unauthorized access for affected users, impacting data confidentiality but not availability or integrity.
Prioritized remediation
Update to nginx ignition version 2.35.1 immediately to patch the issue.
auth-bypasswebotpsecurity-update

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-287

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.