CVE-2026-102334

CVE-2026-102334 published: Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently ...

View full NVD advisory → ← Back to CVE watch