Junglewise Threat Intelligence

CVE-2026-35175: Ajenti authorization bypass in package installation

CVE-2026-35175 · Severity: medium · CVSS 6.5 · Published 2026-04-06

Technologies: ajenti-panel (PyPI), Ajenti. Vendors: PyPI, Ajenti.

Executive brief

Ajenti is a server administration panel used to manage Linux and BSD systems through a web interface. A security flaw allowed standard users to install custom software packages on the server, a task normally reserved for administrators. This could allow a non-privileged user to modify system configurations or install unauthorized software, potentially compromising the server's integrity.

Technical details

A missing authorization vulnerability (CWE-862) exists in Ajenti's task handling logic. When the 'auth_users' plugin is used for authentication, the system fails to properly verify if a user has superuser privileges before allowing the installation of custom packages. An authenticated attacker with low privileges can exploit this over the network to install arbitrary packages on the host system. This bypasses intended role-based access controls. The issue is addressed in version 2.2.15 by implementing stricter checks on tasks.

Affected products

  • Ajenti Ajenti < 2.2.15

Timeline

  • 2026-03-31: patched: Version 2.2.15 released
  • 2026-04-01: advisory: GitHub Security Advisory published
  • 2026-04-06: disclosed: CVE published to NVD

References

Related threats