Junglewise Threat Intelligence

CVE-2026-40177: Ajenti plugin core password bypass when 2FA is enabled

CVE-2026-40177 · Severity: high · CVSS 7.5 · Published 2026-04-10

Vendors: Ajenti, PyPI.

Executive brief

Ajenti plugin core allows attackers to bypass password authentication when two-factor authentication (2FA) is enabled. This vulnerability affects versions prior to 0.112 and is resolved in the 0.112 release.

Affected products

  • ajenti ajenti_plugin_core
  • PyPI ajenti-plugin-core

References

Related threats