Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue. | |
| Title | nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T15:12:59.314Z
Reserved: 2026-07-10T17:38:57.110Z
Link: CVE-2026-61628
Updated: 2026-09-21T15:12:47.399Z
Status : Received
Published: 2026-09-21T15:17:30.290
Modified: 2026-09-21T15:17:30.290
Link: CVE-2026-61628
No data.
OpenCVE Enrichment
Updated: 2026-09-21T16:30:11Z
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')