CVE-2026-103105: Pexip Infinity
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
Affected products
- Pexip Pexip Infinity: before 38.2 (fixed in 38.2); from 39.0, up to and including 39.1; version 40.0 only
Published 2026-09-30. Last modified 2026-10-05.