CVE-2026-35175

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Ajenti es un panel de administración de servidor modular para Linux y BSD. Antes de la 2.2.15, un usuario autenticado (utilizando el método de autenticación del plugin auth_users) podía instalar un paquete personalizado incluso si este usuario no es superusuario. Esta vulnerabilidad está corregida en la 2.2.15.

20 Apr 2026, 18:33

Type Values Removed Values Added
First Time Ajenti
Ajenti ajenti
References () https://github.com/ajenti/ajenti/releases/tag/v2.2.15 - () https://github.com/ajenti/ajenti/releases/tag/v2.2.15 - Product, Release Notes
References () https://github.com/ajenti/ajenti/security/advisories/GHSA-73jv-44c3-j5p2 - () https://github.com/ajenti/ajenti/security/advisories/GHSA-73jv-44c3-j5p2 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:*

06 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 18:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35175

Mitre link : CVE-2026-35175

CVE.ORG link : CVE-2026-35175


JSON object : View

Products Affected

ajenti

  • ajenti
CWE
CWE-862

Missing Authorization