OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103105

HIGH · CVSS 8.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Pexip Infinity versions prior to 38.2, as well as 39.0, 39.1, and 40.0, are vulnerable due to improper access control on an internal API, enabling local attackers to execute arbitrary code on other nodes within the installation. This vulnerability poses a significant risk as it allows unprivileged users to compromise the integrity of the system. Organizations using affected versions should prioritize remediation to prevent potential exploitation and safeguard their infrastructure.

CVE
CVE-2026-103105
Severity
HIGH
CVSS
8.8
EPSS
0.18%

Original NVD Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

Related CVEs

Other vulnerabilities affecting the same vendor(s)