<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nginx Proxy Manager (&lt;= 2.16.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nginx-proxy-manager--2.16.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 00:23:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nginx-proxy-manager--2.16.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Nginx Proxy Manager Authentication Brute-Force Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/</link><pubDate>Tue, 29 Sep 2026 00:23:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102334-npm-brute-force/</guid><description>Nginx Proxy Manager versions 2.16.0 and earlier lack rate-limiting on authentication endpoints, enabling unauthenticated attackers to perform credential stuffing and bypass MFA via brute-force.</description><content:encoded><![CDATA[<p>Nginx Proxy Manager (NPM) versions 2.16.0 and earlier contain a security vulnerability resulting from missing rate-limiting mechanisms on critical authentication endpoints. This flaw allows unauthenticated remote attackers to perform high-velocity password guessing (credential stuffing) against the <code>/api/tokens</code> endpoint. Furthermore, once a valid password is discovered, the lack of rate-limiting extends to the <code>/api/tokens/2fa</code> endpoint, allowing attackers to brute-force Time-based One-Time Password (TOTP) codes. Successful exploitation grants an attacker full session access and administrative control over the proxy instance. This vulnerability presents a significant risk to organizations managing reverse proxy infrastructure, as it provides an entry point for lateral movement or configuration modification via compromised administrative accounts. Defenders should monitor web access logs for anomalous request volumes targeting these specific API paths.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify the NPM web interface and associated login API paths.</li>
<li>Attacker initiates a high-volume POST request flood against <code>/api/tokens</code> to brute-force account passwords.</li>
<li>Attacker identifies a valid set of credentials through successful HTTP 200 responses.</li>
<li>Attacker submits valid credentials to the <code>/api/tokens</code> endpoint to establish an initial session or receive a partial authentication state.</li>
<li>Attacker initiates a high-volume POST request flood against <code>/api/tokens/2fa</code> using the valid session/password.</li>
<li>Attacker successfully guesses the correct TOTP code, triggering an HTTP response indicating successful authentication.</li>
<li>Attacker gains full administrative session tokens.</li>
<li>Attacker uses administrative access to modify proxy configurations, intercept traffic, or exfiltrate sensitive backend data.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to achieve full administrative control over Nginx Proxy Manager instances. This can lead to total compromise of managed traffic, potential data exfiltration from proxied backends, or the redirection of user traffic to malicious infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Audit webserver access logs for high-frequency POST requests to <code>/api/tokens</code> and <code>/api/tokens/2fa</code> originating from single or distributed IP addresses.</li>
<li>Implement request rate-limiting at the WAF or reverse-proxy level (e.g., Nginx 'limit_req' module) for the affected API paths as a temporary mitigation until the software is updated.</li>
<li>Monitor for multiple consecutive HTTP 401 or 403 responses followed by a single 200 response on the authentication endpoints.</li>
<li>Enforce IP-based allowlisting for access to the Nginx Proxy Manager administrative dashboard and API endpoints.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>access-control</category><category>proxy</category></item></channel></rss>