CVE-2026-102334: Brute-Force Risk in Nginx Proxy Manager
This text was generated using artificial intelligence (AI).CVE-2026-102334 affects Nginx Proxy Manager up to and including version 2.16.0. According to NVD, there are no limits on repeated login attempts at authentication endpoints. Unauthenticated attackers can thus test passwords against accounts without restriction.
After a successful password attempt, they can also check TOTP codes. If the login is successful, full session access and administrative control are possible.
The vulnerability is classified as CWE-307. It affects two endpoints:
POST /api/tokens for password attempts
POST /api/tokens/2fa for checking TOTP codes
TOTP refers to time-based one-time passwords as an additional authentication factor. If there is also no limit on attempts during TOTP verification, this step can be repeatedly automated.
CVE-2026-102334 is rated with a CVSS score of 9.1 (v4.0). The documented CVSS vector describes an attack over the network with low attack complexity, without prior permissions, and without user interaction — while the vector specifies certain deployment conditions as prerequisites.
Check Affectedness and Protective Measures
Organizations should first check if Nginx Proxy Manager is used up to and including version 2.16.0 and whether the authentication endpoints are accessible. The check particularly concerns instances where administrative access is reachable via HTTP(S).
The associated rate-limiting fix is implemented in Pull Request #5908 of the project. A specific cleaned-up release version is not named in the available sources. As soon as a release above version 2.16.0 is available, it should be assessed and updated promptly.
As long as no officially patched release is available, the present measure description recommends upstream network controls. Rate limits at a reverse proxy or a web application firewall can limit access to both endpoints:
POST /api/tokens
POST /api/tokens/2fa
The limitation should cover password attempts and TOTP verifications. Additionally, affected systems should be prioritized, and the patch status documented.
For organizations in Germany and Austria that fall under NIS-2 or the Austrian NISG, documentation of exposed services and a traceable patch process count as operational security duties. In Switzerland, similar requirements apply from the revised Information Security Act (ISG) and the reporting obligation to BACS. In the event of a successful compromise leading to a data protection incident with personal reference, the 72-hour notification period under Article 33 GDPR applies to organizations in the EU.
Prioritization of Publicly Accessible Instances
CVE-2026-102334 is relevant for publicly accessible Nginx Proxy Manager instances because the login endpoint can be immediately accessible via HTTP(S). Therefore, three questions are helpful for prioritization:
Is a Nginx Proxy Manager instance externally accessible?
Is an affected product version being used?
Do upstream rate limits apply to both authentication endpoints?
The responses support the classification of which systems should be tested and mitigated first. An external view of reachable services complements internal asset data, especially for forgotten or instances hosted under their own domains.
Visibility of Exposed Services
LocateRisk supports External Attack Surface Management in identifying externally reachable systems and deployed software. In the context of CVE-2026-102334, exposed Nginx Proxy Manager instances can be considered a risk in prioritization. The visibility of an instance does not automatically confirm the specific vulnerable product version; patch status and impact require further examination.
For vendor relationships, Cyber Vendor Risk Management can continuously monitor changes in the security level of third parties and categorize them into risk processes. LocateRisk is Made in Germany, is operated exclusively in German data centers, and does not process any data through US providers.
Am I affected?
This affects Nginx Proxy Manager in the versions mentioned above. Anyone wanting to know if Nginx Proxy Manager is visible in their externally reachable infrastructure can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-102334 is a vulnerability in Nginx Proxy Manager up to and including version 2.16.0. It describes the lack of rate limits at the authentication endpoints POST /api/tokens and POST /api/tokens/2fa, which allows unauthenticated attackers to attempt passwords and TOTP codes without limit. The vulnerability is classified as CWE-307 and rated with CVSS 9.1 (v4.0).
This affects all versions of Nginx Proxy Manager up to and including 2.16.0. A officially released fixed version has not been named at the time of this information. A rate limiting fix is being worked on in Pull Request #5908 of the project; as soon as a release is available, it should be applied promptly.
Upstream network controls are recommended: rate limits at a reverse proxy or a web application firewall that cover both POST /api/tokens and POST /api/tokens/2fa . Publicly accessible instances should be prioritized for review, and management access should be restricted to necessary network segments.
As of: September 29, 2026. This contribution is for general informational purposes and is not legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always decisive. Despite careful research, we accept no liability for the timeliness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-102334
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.