PT-2026-32032 · Ajenti · Ajenti

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-40178

CVSS v4.0

6.9

Medium

AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.

Fix

Race Condition

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-40178

Affected Products

Ajenti