Skip to content
Threat Feed
high advisory

Nginx Proxy Manager Authentication Brute-Force Vulnerability

Nginx Proxy Manager versions 2.16.0 and earlier lack rate-limiting on authentication endpoints, enabling unauthenticated attackers to perform credential stuffing and bypass MFA via brute-force.

CVE search metadata

CVE search record: CVE-2026-102334. Severity: high. CVSS: 7.4. KEV: no. Product: Nginx Proxy Manager (<= 2.16.0). Brief: Nginx Proxy Manager Authentication Brute-Force Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/

What's new

  • 1. added coverage for Nginx Proxy Manager (<= 2.16.0) Sep 29, 00:24 via nvd

Nginx Proxy Manager (NPM) versions 2.16.0 and earlier contain a security vulnerability resulting from missing rate-limiting mechanisms on critical authentication endpoints. This flaw allows unauthenticated remote attackers to perform high-velocity password guessing (credential stuffing) against the /api/tokens endpoint. Furthermore, once a valid password is discovered, the lack of rate-limiting extends to the /api/tokens/2fa endpoint, allowing attackers to brute-force Time-based One-Time Password (TOTP) codes. Successful exploitation grants an attacker full session access and administrative control over the proxy instance. This vulnerability presents a significant risk to organizations managing reverse proxy infrastructure, as it provides an entry point for lateral movement or configuration modification via compromised administrative accounts. Defenders should monitor web access logs for anomalous request volumes targeting these specific API paths.

Attack Chain

  1. Attacker performs reconnaissance to identify the NPM web interface and associated login API paths.
  2. Attacker initiates a high-volume POST request flood against /api/tokens to brute-force account passwords.
  3. Attacker identifies a valid set of credentials through successful HTTP 200 responses.
  4. Attacker submits valid credentials to the /api/tokens endpoint to establish an initial session or receive a partial authentication state.
  5. Attacker initiates a high-volume POST request flood against /api/tokens/2fa using the valid session/password.
  6. Attacker successfully guesses the correct TOTP code, triggering an HTTP response indicating successful authentication.
  7. Attacker gains full administrative session tokens.
  8. Attacker uses administrative access to modify proxy configurations, intercept traffic, or exfiltrate sensitive backend data.

Impact

Successful exploitation allows unauthenticated attackers to achieve full administrative control over Nginx Proxy Manager instances. This can lead to total compromise of managed traffic, potential data exfiltration from proxied backends, or the redirection of user traffic to malicious infrastructure.

Recommendation

  1. Audit webserver access logs for high-frequency POST requests to /api/tokens and /api/tokens/2fa originating from single or distributed IP addresses.
  2. Implement request rate-limiting at the WAF or reverse-proxy level (e.g., Nginx 'limit_req' module) for the affected API paths as a temporary mitigation until the software is updated.
  3. Monitor for multiple consecutive HTTP 401 or 403 responses followed by a single 200 response on the authentication endpoints.
  4. Enforce IP-based allowlisting for access to the Nginx Proxy Manager administrative dashboard and API endpoints.

Immediate actions

Review access logs for high-frequency requests to /api/tokens

SOC 24h

Mitigations

Implement Nginx rate-limiting on /api/tokens and /api/tokens/2fa endpoints

immediate IT Operations

CVE-2026-102334

Detection coverage 1

Detect CVE-2026-102334 Exploitation - Brute-Force Attempt on NPM API

high

Detects potential brute-force attempts against Nginx Proxy Manager authentication endpoints by identifying high-frequency POST requests to /api/tokens or /api/tokens/2fa.

sigma tactics: credential_access techniques: T1110.001 sources: webserver

Detection queries are available on the platform. Get full rules →