CVE-2026-27975

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:*

History

02 Mar 2026, 17:24

Type Values Removed Values Added
References () https://github.com/ajenti/ajenti/releases/tag/v2.2.13 - () https://github.com/ajenti/ajenti/releases/tag/v2.2.13 - Product, Release Notes
References () https://github.com/ajenti/ajenti/security/advisories/GHSA-vcw3-r3fx-j444 - () https://github.com/ajenti/ajenti/security/advisories/GHSA-vcw3-r3fx-j444 - Patch, Vendor Advisory
CWE NVD-CWE-noinfo
First Time Ajenti
Ajenti ajenti
CPE cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Ajenti es un panel de administración de servidor modular para Linux y BSD. Antes de la versión 2.2.13, un usuario no autenticado podría obtener acceso a un servidor para ejecutar código arbitrario en este servidor. Esto está corregido en la versión 2.2.13.

26 Feb 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 03:16

Updated : 2026-03-02 17:24


NVD link : CVE-2026-27975

Mitre link : CVE-2026-27975

CVE.ORG link : CVE-2026-27975


JSON object : View

Products Affected

ajenti

  • ajenti
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo