CVE-2026-103105
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Pexip | Infinity | 0 < 38.2.0 | affected |
| Pexip | Infinity | 39.0.0 | affected |
| Pexip | Infinity | 39.1.0 | affected |
| Pexip | Infinity | 40.0.0 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.