PT-2026-96164 · Ajenti · Ajenti
CVE-2026-79920
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ajenti versions prior to 2.2.16
Description
Authenticated users can access the '/api/core/tasks/start' endpoint to enqueue the
InstallPlugin, UnInstallPlugin, or UpgradeAll functions from 'plugins/plugins/tasks.py' without requiring plugin-management authorization. The InstallPlugin and UnAllPlugin functions create a pip package specification using unvalidated name and version fields. Because the task worker executes pip with root privileges, a low-privileged user can manipulate package installations to execute arbitrary code as root, leading to full host compromise.Recommendations
Update Ajenti to version 2.2.16.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ajenti