<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:46:03.219189+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372930</id>
    <title>EUVD-2026-372930</title>
    <updated>2026-10-06T08:46:03.222743+00:00</updated>
    <content>EUVD-2026-372930</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61628</id>
    <title>fkie_cve-2026-61628</title>
    <updated>2026-10-06T08:46:03.222780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61628"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pxcx-fv34-x9p5</id>
    <title>GHSA-pxcx-fv34-x9p5 — nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition</title>
    <updated>2026-10-06T08:46:03.222819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/lucasdillmann/nginx-ignition</p>
<p>## Summary</p>
<p>`POST /api/users/onboarding/finish` is registered as **anonymous (unauthenticated)** and creates a user with **full ReadWrite admin permissions**. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race.</p>
<p>## Affected component</p>
<p>- Endpoint: `POST /api/users/onboarding/finish`
- Route registration: `api/user/routes.go:49` → `authorizer.AllowAnonymous(http.MethodPost, "/api/users/onboarding/finish")`
- Handler: `api/user/onboarding_finish_handler.go`</p>
<p>## Technical details</p>
<p>The route is explicitly allowed without authentication:</p>
<p>```go
// api/user/routes.go:48-49
authorizer.AllowAnonymous(http.MethodGet,  "/api/users/onboarding/status")
authorizer.AllowAnonymous(http.MethodPost, "/api/users/onboarding/finish")
```</p>
<p>The handler reads the onboarding state, returns 403 if already finished, and otherwise creates a user with every permission set to ReadWrite:</p>
<p>```go
// api/user/onboarding_finish_handler.go
func (h onboardingFinishHandler) handle(ctx *gin.Context) {
    alreadyFinished, err := h.commands.OnboardingCompleted(ctx.Request.Context())  // (1) CHECK
    if err != nil { panic(err) }
    if alreadyFinished {
        ctx.Status(http.StatusForbidden)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pxcx-fv34-x9p5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-61628</id>
    <title>Withdrawn: UBUNTU-CVE-2026-61628</title>
    <updated>2026-10-06T08:46:03.222887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:Pro:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx, Ubuntu:26.04:LTS: nginx</p>
<p>nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-61628"/>
  </entry>
</feed>
