PT-2026-32031 · Ajenti · Ajenti-Plugin-Core

CVE-2026-40177

·

Published

2026-04-10

·

Updated

2026-06-29

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ajenti.plugin.core versions prior to 0.112
Description Prior to version 0.112, if two-factor authentication (2FA) was enabled, password authentication could be bypassed. This allowed unauthorized access to the system.
Recommendations Upgrade to version 0.112 to resolve this issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40177
GHSA-3MCX-6WXM-QR8V
PYSEC-2026-266

Affected Products

Ajenti-Plugin-Core