PT-2026-103011 · Pexip · Pexip Infinity
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pexip Infinity versions prior to 38.2
Pexip Infinity version 39.0
Pexip Infinity version 39.1
Pexip Infinity version 40.0
Description
Improper input validation within an internal service allows an attacker with local access to escalate privileges to root. This requires the attacker to already be capable of running arbitrary code on a node, either through a separate remote code execution flaw or by possessing administrative access to the operating system.
Recommendations
Update Pexip Infinity versions prior to 38.2 to version 38.2 or later.
Update Pexip Infinity version 39.0 to a patched release.
Update Pexip Infinity version 39.1 to a patched release.
Update Pexip Infinity version 40.0 to a patched release.
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pexip Infinity