CVE-2026-103105: Pexip Infinity

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

Affected products

  • Pexip Pexip Infinity: before 38.2 (fixed in 38.2); from 39.0, up to and including 39.1; version 40.0 only

Published 2026-09-30. Last modified 2026-10-05.