Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40177

Опубликовано: 10 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ajenti:ajenti_plugin_core:*:*:*:*:*:*:*:*
Версия до 0.112 (исключая)

EPSS

Процентиль: 26%
0.00329
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
debian
4 месяца назад

ajenti.plugin.core defines all necessary core elements to allow Ajenti ...

CVSS3: 7.5
github
4 месяца назад

ajenti.plugin.core has password bypass when 2FA is activated

EPSS

Процентиль: 26%
0.00329
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
NVD-CWE-noinfo