CVE-2026-61630EPSS p29.7%
CVE-2026-61630CVE-2026-61630
Description
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
Scoring
| CVSS | 4.2 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N |
| EPSS | 0.38% probability of exploitation · percentile 29.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |