CVE-2026-103105

Summary

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

Affected Software

VendorProductVersion RangeStatus
PexipInfinity0 < 38.2.0affected
PexipInfinity39.0.0affected
PexipInfinity39.1.0affected
PexipInfinity40.0.0affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

References