PT-2026-103011 · Pexip · Pexip Infinity

·

CVE-2026-103106

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pexip Infinity versions prior to 38.2 Pexip Infinity version 39.0 Pexip Infinity version 39.1 Pexip Infinity version 40.0
Description Improper input validation within an internal service allows an attacker with local access to escalate privileges to root. This requires the attacker to already be capable of running arbitrary code on a node, either through a separate remote code execution flaw or by possessing administrative access to the operating system.
Recommendations Update Pexip Infinity versions prior to 38.2 to version 38.2 or later. Update Pexip Infinity version 39.0 to a patched release. Update Pexip Infinity version 39.1 to a patched release. Update Pexip Infinity version 40.0 to a patched release.

Fix

LPE

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103106

Affected Products

Pexip Infinity