Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40178

Опубликовано: 10 апр. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ajenti:ajenti_plugin_core:*:*:*:*:*:*:*:*
Версия до 0.112 (исключая)

EPSS

Процентиль: 14%
0.00232
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.9
debian
4 месяца назад

ajenti.plugin.core defines all necessary core elements to allow Ajenti ...

CVSS3: 5.9
github
4 месяца назад

ajenti.plugin.core has race conditions in 2FA

EPSS

Процентиль: 14%
0.00232
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287