Unauthenticated Admin Account Creation in nginx ignition via Onboarding Race Condition
A critical vulnerability (CVE-2026-61628) in nginx ignition allows unauthenticated attackers to create admin accounts with full ReadWrite permissions. The vulnerability stems from a TOCTOU (time-of-check to time-of-use) race condition in the onboarding process. Attackers can exploit this during the fresh deployment or if the onboarding state is reset. Immediate patching or mitigation is crucial to prevent unauthorized admin access.