CVE-2026-61630 Details
Description
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
A vulnerability exists in nginx Ignition versions 2.33.0 through 2.35.0, allowing users with two-factor authentication (2FA) enabled to reuse their time-based one-time passwords (TOTP) within the standard 30-second validity period. This issue arises because the authentication package used does not prevent the reuse of TOTPs during their validity window, requiring applications to implement their own safeguards.
Users can update to nginx Ignition version 2.35.1, which addresses this vulnerability by implementing proper TOTP reuse prevention. After updating, it's recommended to review and manage any existing TOTP codes to ensure they are not reused.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lucasdillmann/nginx-ignition | >= 2.33.0, <= 2.35.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion