Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://docs.pexip.com/admin/security_bulletins.htm |
|
History
Wed, 30 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node. | |
| First Time appeared |
Pexip
Pexip infinity |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pexip
Pexip infinity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-30T02:39:23.072Z
Reserved: 2026-09-30T02:39:22.113Z
Link: CVE-2026-103105
No data.
Status : Received
Published: 2026-09-30T03:16:59.623
Modified: 2026-09-30T03:16:59.623
Link: CVE-2026-103105
No data.
OpenCVE Enrichment
Updated: 2026-09-30T07:15:04Z
Weaknesses