PT-2026-103010 · Pexip · Pexip Infinity

CVE-2026-103105

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pexip Infinity versions prior to 38.2 Pexip Infinity version 39.0 Pexip Infinity version 39.1 Pexip Infinity version 40.0
Description Improper access control on a product-internal API allows an attacker with local access to a node within an installation to execute arbitrary code as an unprivileged user on another node.
Recommendations Update Pexip Infinity to version 38.2 or later. Update Pexip Infinity to a version newer than 39.0. Update Pexip Infinity to a version newer than 39.1. Update Pexip Infinity to a version newer than 40.0.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103105

Affected Products

Pexip Infinity