CVE-2026-103110: Pexip Infinity

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

Affected products

  • Pexip Pexip Infinity: before 38.2 (fixed in 38.2); from 39.0, up to and including 39.1; version 40.0 only

Published 2026-09-30. Last modified 2026-10-05.