CVE-2026-61630 Overview
CVE-2026-61630 is an authentication weakness in nginx ignition, a user interface for the nginx web server. Versions 2.33.0 through 2.35.0 allow reuse of a Time-based One-Time Password (TOTP) within the standard 30-second validity window when Two-Factor Authentication (2FA) is enabled. An attacker who obtains a valid TOTP code can replay it during that window to complete authentication as the victim. The maintainer released version 2.35.1 to address the flaw. The issue is classified under [CWE-287: Improper Authentication].
Critical Impact
A captured TOTP code can be replayed within its 30-second lifetime, undermining the single-use guarantee expected from 2FA and enabling account takeover when combined with a leaked or intercepted OTP.
Affected Products
- nginx ignition version 2.33.0
- nginx ignition versions 2.34.x
- nginx ignition version 2.35.0
Discovery Timeline
- 2026-09-21 - CVE-2026-61630 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-61630
Vulnerability Analysis
nginx ignition provides a web-based administrative interface for managing nginx configurations. Users can enable TOTP-based 2FA to strengthen login security. The RFC 6238 TOTP specification defines codes as valid for a fixed step, typically 30 seconds, and implementations are expected to reject any previously accepted code within that step to prevent replay.
In versions 2.33.0 through 2.35.0, the authentication flow validates the current TOTP value but does not persist the last-used code or timestep against the user record. An attacker who observes a code through shoulder-surfing, phishing, a malicious browser extension, or network interception on an intermediary can submit the same value in a second authentication request before the 30-second window elapses.
Root Cause
The root cause is a missing anti-replay check in the OTP verification path. TOTP validation confirms the numeric code matches the expected value for the current timestep but does not record the consumed step for the account. Without a used-code cache or last-successful-step counter, the server treats every submission within the window as fresh.
Attack Vector
Exploitation requires an attacker to obtain a live TOTP for a target account with high-privilege access and coax the user into initiating an interaction that exposes it. The CVSS vector AV:N/AC:H/PR:H/UI:R reflects the network reachability of the login endpoint alongside the difficulty of collecting a still-valid code. Because impact is limited to confidentiality of authenticated actions, integrity and availability are unaffected in the base score.
Patch Reference
The fixes were delivered across two commits in the upstream repository. The changes touch the 2FA authentication path and dependency hygiene rather than a single isolated function.
// Snippet from api/certificate/converter.go in the 2FA fix commit
) *issueCertificateResponse {
var errorReason *string
if err != nil {
- errorStr := err.Error()
- errorReason = &errorStr
+ errorReason = new(err.Error())
}
var certificateID *uuid.UUID
Source: GitHub Commit 1cbfae0 - 2FA (#92)
A follow-on commit bumped transitive dependencies as part of the security release.
-github.com/bytedance/sonic/loader v0.5.0
+github.com/bytedance/sonic/loader v0.5.1
Source: GitHub Commit 8d35e1e - Security fixes (#104)
Detection Methods for CVE-2026-61630
Indicators of Compromise
- Multiple successful 2FA validations for the same account originating from different source IP addresses within a 30-second window.
- Repeated identical OTP submissions to the nginx ignition login endpoint from distinct user agents.
- Session creation events for administrative users immediately following a legitimate login from a different network segment.
Detection Strategies
- Alert on any nginx ignition login where the interval between two successful authentications for the same principal is under 30 seconds.
- Correlate authentication logs with reverse-proxy access logs to identify divergent client fingerprints reusing OTP submissions.
- Baseline normal administrator login geography and flag anomalous source ASN or country appearing during the OTP validity window.
Monitoring Recommendations
- Forward nginx ignition application logs and web server access logs to a centralized logging platform for correlation.
- Enable detailed audit logging of authentication attempts, including timestamp precision to the millisecond.
- Monitor for privilege changes, nginx configuration edits, or certificate operations performed shortly after login events flagged by the rules above.
How to Mitigate CVE-2026-61630
Immediate Actions Required
- Upgrade nginx ignition to version 2.35.1 or later, which enforces single-use TOTP validation.
- Rotate 2FA seeds for all administrative accounts after upgrading to invalidate any previously captured secrets.
- Review authentication and administrative action logs from the exposure window for evidence of replayed sessions.
Patch Information
Upgrade to nginx ignition version 2.35.1. The fix is documented in the GitHub Security Advisory GHSA-hf33-q6cf-c66f and corresponding commits 1cbfae0 and 8d35e1e.
Workarounds
- Restrict access to the nginx ignition management interface to a trusted management network or VPN to reduce exposure of the login endpoint.
- Place the interface behind a reverse proxy that enforces mutual TLS or IP allow-listing for administrators.
- Require administrators to log out promptly and avoid submitting OTPs on shared or untrusted devices until the upgrade is complete.
# Verify the running nginx ignition version and upgrade
nginx-ignition --version
# Example upgrade via container image tag
docker pull lucasdillmann/nginx-ignition:2.35.1
docker stop nginx-ignition && docker rm nginx-ignition
docker run -d --name nginx-ignition \
-p 8090:8090 \
-v /opt/nginx-ignition:/data \
lucasdillmann/nginx-ignition:2.35.1
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.