PT-2026-96164 · Ajenti · Ajenti

CVE-2026-79920

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ajenti versions prior to 2.2.16
Description Authenticated users can access the '/api/core/tasks/start' endpoint to enqueue the InstallPlugin, UnInstallPlugin, or UpgradeAll functions from 'plugins/plugins/tasks.py' without requiring plugin-management authorization. The InstallPlugin and UnAllPlugin functions create a pip package specification using unvalidated name and version fields. Because the task worker executes pip with root privileges, a low-privileged user can manipulate package installations to execute arbitrary code as root, leading to full host compromise.
Recommendations Update Ajenti to version 2.2.16.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79920
GHSA-J8XF-5FW2-F99Q

Affected Products

Ajenti