CVE-2026-61628 | lucasdillmann Nginx Ignition up to 2.41.0 finish toctou

SecurityVulns

A vulnerability was found in lucasdillmann Nginx Ignition up to 2.41.0. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/users/onboarding/finish. This manipulation causes time-of-check time-of-use.

This vulnerability appears as CVE-2026-61628. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More