Junglewise Threat Intelligence

CVE-2026-40178: Ajenti 2FA authentication bypass in ajenti.plugin.core

CVE-2026-40178 · Severity: medium · CVSS 5.9 · Published 2026-04-10

Vendors: Ajenti, PyPI.

Executive brief

Ajenti suffers from a race condition in its core plugin that allows attackers to bypass two-factor authentication (2FA) during a brief window following initial user authentication.

Affected products

  • ajenti ajenti_plugin_core
  • PyPI ajenti-plugin-core

References

Related threats