CVE-2026-61630
4.2 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows any user with OTP 2FA enabled to reuse their TOTP during a 30-second window, potentially leading to unauthorized access.
- Exploitability
- Exploitation requires a user who has enabled OTP 2FA and can manipulate the timing of their authentication within the validity window; moderately difficult.
- Blast radius
- If exploited, this could result in unauthorized access for affected users, impacting data confidentiality but not availability or integrity.
- Prioritized remediation
- Update to nginx ignition version 2.35.1 immediately to patch the issue.
auth-bypasswebotpsecurity-update
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-287
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15372
- HIGHCVE-2026-16036
- HIGHCVE-2026-16055
- HIGHCVE-2026-61687PoC
- CRITICALCVE-2026-63456
- HIGHCVE-2026-70482PoC
- CRITICALCVE-2026-71277PoC
- MEDIUMCVE-2026-94151PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.