PT-2026-103010 · Pexip · Pexip Infinity
CVE-2026-103105
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pexip Infinity versions prior to 38.2
Pexip Infinity version 39.0
Pexip Infinity version 39.1
Pexip Infinity version 40.0
Description
Improper access control on a product-internal API allows an attacker with local access to a node within an installation to execute arbitrary code as an unprivileged user on another node.
Recommendations
Update Pexip Infinity to version 38.2 or later.
Update Pexip Infinity to a version newer than 39.0.
Update Pexip Infinity to a version newer than 39.1.
Update Pexip Infinity to a version newer than 40.0.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pexip Infinity