Nginx Proxy Manager Authentication Brute-Force Vulnerability
Nginx Proxy Manager versions 2.16.0 and earlier lack rate-limiting on authentication endpoints, enabling unauthenticated attackers to perform credential stuffing and bypass MFA via brute-force.
CVE search metadata
CVE search record: CVE-2026-102334. Severity: high. CVSS: 7.4. KEV: no. Product: Nginx Proxy Manager (<= 2.16.0). Brief: Nginx Proxy Manager Authentication Brute-Force Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/
What's new
- 1. added coverage for Nginx Proxy Manager (<= 2.16.0) Sep 29, 00:24 via nvd
Nginx Proxy Manager (NPM) versions 2.16.0 and earlier contain a security vulnerability resulting from missing rate-limiting mechanisms on critical authentication endpoints. This flaw allows unauthenticated remote attackers to perform high-velocity password guessing (credential stuffing) against the /api/tokens endpoint. Furthermore, once a valid password is discovered, the lack of rate-limiting extends to the /api/tokens/2fa endpoint, allowing attackers to brute-force Time-based One-Time Password (TOTP) codes. Successful exploitation grants an attacker full session access and administrative control over the proxy instance. This vulnerability presents a significant risk to organizations managing reverse proxy infrastructure, as it provides an entry point for lateral movement or configuration modification via compromised administrative accounts. Defenders should monitor web access logs for anomalous request volumes targeting these specific API paths.
Attack Chain
- Attacker performs reconnaissance to identify the NPM web interface and associated login API paths.
- Attacker initiates a high-volume POST request flood against
/api/tokensto brute-force account passwords. - Attacker identifies a valid set of credentials through successful HTTP 200 responses.
- Attacker submits valid credentials to the
/api/tokensendpoint to establish an initial session or receive a partial authentication state. - Attacker initiates a high-volume POST request flood against
/api/tokens/2fausing the valid session/password. - Attacker successfully guesses the correct TOTP code, triggering an HTTP response indicating successful authentication.
- Attacker gains full administrative session tokens.
- Attacker uses administrative access to modify proxy configurations, intercept traffic, or exfiltrate sensitive backend data.
Impact
Successful exploitation allows unauthenticated attackers to achieve full administrative control over Nginx Proxy Manager instances. This can lead to total compromise of managed traffic, potential data exfiltration from proxied backends, or the redirection of user traffic to malicious infrastructure.
Recommendation
- Audit webserver access logs for high-frequency POST requests to
/api/tokensand/api/tokens/2faoriginating from single or distributed IP addresses. - Implement request rate-limiting at the WAF or reverse-proxy level (e.g., Nginx 'limit_req' module) for the affected API paths as a temporary mitigation until the software is updated.
- Monitor for multiple consecutive HTTP 401 or 403 responses followed by a single 200 response on the authentication endpoints.
- Enforce IP-based allowlisting for access to the Nginx Proxy Manager administrative dashboard and API endpoints.
Immediate actions
Review access logs for high-frequency requests to /api/tokens
Mitigations
Implement Nginx rate-limiting on /api/tokens and /api/tokens/2fa endpoints
CVE-2026-102334
Detection coverage 1
Detect CVE-2026-102334 Exploitation - Brute-Force Attempt on NPM API
highDetects potential brute-force attempts against Nginx Proxy Manager authentication endpoints by identifying high-frequency POST requests to /api/tokens or /api/tokens/2fa.
Detection queries are available on the platform. Get full rules →