CVE-2026-61628 is a race condition in nginx-ignition versions earlier than 2.41.1. The anonymously accessible onboarding-completion API uses a non-atomic check-then-act flow to determine whether initial onboarding has already completed and then create an initial user. Concurrent requests can each observe that no user exists and proceed to create accounts with full ReadWrite administrative permissions. Version 2.41.1 replaces this flow with transactional initial-user creation and exclusive user-table locking.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is an operational Python proof of concept for CVE-2026-61628, a CWE-362 check-then-act race in nginx-ignition onboarding. The main entry point, CVE-2026-61628-Abraxas-Labs.py, targets the anonymous POST /api/users/onboarding/finish route. It issues concurrent onboarding requests to race the non-atomic onboarding-completed check and user save, captures successful JWT-bearing responses, then validates the first JWT through /api/users/current and lists users through /api/users. The demonstrated impact is unauthenticated administrator-account creation, potentially multiple accounts in one request burst; it is explicitly not an RCE or shell payload. README.md documents the affected range through 2.41.0 and the remediation in 2.41.1. The lab directory provides a Docker Compose environment with nginx-ignition 2.41.0, PostgreSQL 16, fixed lab database credentials, a lab JWT secret, and a loopback-only host port binding. Supporting files are an AGPL-3.0 license and git-ignore rules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity unauthenticated race-condition privilege-escalation flaw in nginx-ignition's pre-onboarding endpoint. An attacker able to reach an instance before onboarding is completed can race the endpoint to provision one or more full ReadWrite administrator accounts.
A network-reachable vulnerability tracked as CVE-2026-61628 affecting Canonical Ubuntu Linux LTS releases 14.04 through 26.04, with high CVSS v3 impacts to confidentiality, integrity, and availability. The content does not describe the underlying flaw type or affected component beyond Ubuntu Linux/nginx package CPE information.
A race condition in Nginx Ignition's onboarding-completion handler permits concurrent unauthenticated requests to bypass the single-initial-user setup assumption and create multiple administrative accounts. The issue is caused by a non-atomic check-then-insert workflow; version 2.41.1 adds a transaction, table lock, and existence check before insertion.
An unauthenticated TOCTOU race condition in nginx-ignition's onboarding completion endpoint permits remote attackers who can access a fresh or reset, pre-onboarding instance to create one or more full-administrator accounts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.