PT-2026-59023 · Pypi · Ajenti-Panel

Published

2026-07-13

·

Updated

2026-07-13

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L

Impact

An authenticated user (using the auth users plugin authentication method) could install a custom package even if this user is not superuser.

Patches

This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2339

Affected Products

Ajenti-Panel