CVE-2026-102334: Brute-Force Risk in Nginx Proxy Manager

This text was generated using artificial intelligence (AI).CVE-2026-102334 affects Nginx Proxy Manager up to and including version 2.16.0. According to NVD, there are no limits on repeated login attempts at authentication endpoints. Unauthenticated attackers can thus test passwords against accounts without restriction.

After a successful password attempt, they can also check TOTP codes. If the login is successful, full session access and administrative control are possible.

Are my systems affected? Check now →