CVE-2026-61630Medium· 4.2▾ Sunlitnginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/lucasdillmann/nginx-ignition >= 0.0.0-20260217145239-1cbfae0296f1, < 0.0.0-20260328015550-8d35e1eb5dd6Patched in:
github.com/lucasdillmann/nginx-ignition 0.0.0-20260328015550-8d35e1eb5dd6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61628High· 8.1nginx ignition is a user interface for the nginx web server
CVE-2026-61629High· 7.5nginx ignition is a user interface for the nginx web server
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1
CVE-2019-1946Medium· 6.5A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management int…
CVE-2020-12812Critical· 9.8An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…