Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40177 +1 in the same advisory: …40178 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112. NVD description · AI analysis pending | 9.3 group max | <1% |
| — | ||
| CVE-2026-35175 | Ajenti is a Linux and BSD modular server admin panel. Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2026-27975 | Ajenti is a Linux and BSD modular server admin panel. Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2019-25066 | A vulnerability has been found in ajenti 2.1.31 and classified as critical. A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component. NVD description · AI analysis pending | 8.8 | 5% | PoC ×2 |
| — | |
| CVE-2018-18548 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. NVD description · AI analysis pending | 6.1 | 4% |
| — | ||
| CVE-2018-1000082 | Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed.. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — |