Executive brief
Ajenti, a server administration panel, contains a security weakness that could allow an attacker to trick users into performing unintended actions. By embedding the Ajenti interface into a malicious website, an attacker could overlap invisible buttons or forms over the legitimate UI. This could lead to unauthorized configuration changes or administrative actions if a logged-in administrator is deceived into clicking on the page.
Technical details
Ajenti through v2.2.13 is vulnerable to clickjacking due to the absence of defensive HTTP headers in its core response path. Specifically, in `ajenti-core/aj/http.py`, the application initializes an empty header list and finalizes responses via WSGI `start_response()` without enforcing `X-Frame-Options` or `Content-Security-Policy: frame-ancestors`. This allows the administrative UI to be rendered within an <iframe> on a remote, attacker-controlled domain. An attacker can exploit this to perform UI redressing attacks against authenticated users. A patch has been identified in the project's repository that explicitly adds these headers if they are not already present.
Affected products
- Ajenti Ajenti through 2.2.13
Timeline
- 2026-07-06: advisory: CVE-2026-38979 published by NVD
- 2026-07-06: disclosed