{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anginxproxymanagernginx_proxy_manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-102334"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nginx Proxy Manager (\u003c= 2.16.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","access-control","proxy"],"_cs_type":"advisory","_cs_vendors":["Nginx Proxy Manager"],"content_html":"\u003cp\u003eNginx Proxy Manager (NPM) versions 2.16.0 and earlier contain a security vulnerability resulting from missing rate-limiting mechanisms on critical authentication endpoints. This flaw allows unauthenticated remote attackers to perform high-velocity password guessing (credential stuffing) against the \u003ccode\u003e/api/tokens\u003c/code\u003e endpoint. Furthermore, once a valid password is discovered, the lack of rate-limiting extends to the \u003ccode\u003e/api/tokens/2fa\u003c/code\u003e endpoint, allowing attackers to brute-force Time-based One-Time Password (TOTP) codes. Successful exploitation grants an attacker full session access and administrative control over the proxy instance. This vulnerability presents a significant risk to organizations managing reverse proxy infrastructure, as it provides an entry point for lateral movement or configuration modification via compromised administrative accounts. Defenders should monitor web access logs for anomalous request volumes targeting these specific API paths.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the NPM web interface and associated login API paths.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a high-volume POST request flood against \u003ccode\u003e/api/tokens\u003c/code\u003e to brute-force account passwords.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a valid set of credentials through successful HTTP 200 responses.\u003c/li\u003e\n\u003cli\u003eAttacker submits valid credentials to the \u003ccode\u003e/api/tokens\u003c/code\u003e endpoint to establish an initial session or receive a partial authentication state.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a high-volume POST request flood against \u003ccode\u003e/api/tokens/2fa\u003c/code\u003e using the valid session/password.\u003c/li\u003e\n\u003cli\u003eAttacker successfully guesses the correct TOTP code, triggering an HTTP response indicating successful authentication.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative session tokens.\u003c/li\u003e\n\u003cli\u003eAttacker uses administrative access to modify proxy configurations, intercept traffic, or exfiltrate sensitive backend data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve full administrative control over Nginx Proxy Manager instances. This can lead to total compromise of managed traffic, potential data exfiltration from proxied backends, or the redirection of user traffic to malicious infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit webserver access logs for high-frequency POST requests to \u003ccode\u003e/api/tokens\u003c/code\u003e and \u003ccode\u003e/api/tokens/2fa\u003c/code\u003e originating from single or distributed IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement request rate-limiting at the WAF or reverse-proxy level (e.g., Nginx 'limit_req' module) for the affected API paths as a temporary mitigation until the software is updated.\u003c/li\u003e\n\u003cli\u003eMonitor for multiple consecutive HTTP 401 or 403 responses followed by a single 200 response on the authentication endpoints.\u003c/li\u003e\n\u003cli\u003eEnforce IP-based allowlisting for access to the Nginx Proxy Manager administrative dashboard and API endpoints.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T00:24:03Z","date_published":"2026-09-29T00:23:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/","summary":"Nginx Proxy Manager versions 2.16.0 and earlier lack rate-limiting on authentication endpoints, enabling unauthenticated attackers to perform credential stuffing and bypass MFA via brute-force.","title":"Nginx Proxy Manager Authentication Brute-Force Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}