PT-2026-32032 · Ajenti · Ajenti-Plugin-Core

CVE-2026-40178

·

Published

2026-04-10

·

Updated

2026-07-13

CVSS v4.0

6.9

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions ajenti.plugin.core versions prior to 0.112
Description Prior to version 0.112, a timing issue allowed bypassing two-factor authentication (2FA) immediately after a user's successful authentication. This occurred during a brief window after authentication but before the 2FA mechanism was fully engaged.
Recommendations Upgrade to version 0.112.

Fix

Race Condition

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40178
GHSA-8647-755Q-FW9P
PYSEC-2026-2340

Affected Products

Ajenti-Plugin-Core