CVE-2026-61628: Unauthenticated Admin Account Creation in nginx ignition
A critical vulnerability in nginx ignition (CVE-2026-61628, CVSS 8.1) allows unauthenticated remote attackers to create admin accounts with full ReadWrite permissions. This is possible due to a TOCTOU (check-then-act) vulnerability in the `POST /api/users/onboarding/finish` endpoint prior to version 2.41.1. Affected users must update to version 2.41.1 or later to mitigate this risk.