CVE-2025-49088: 
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2025-49088 is an Improper Input Validation vulnerability (CWE-617: Reachable Assertion) in the OTJ (One Touch Join) service of Pexip Infinity, affecting versions 32.0 through 37.1 before 37.2. The flaw is present only in certain configurations of OTJ for Teams SIP Guest Join, and allows a remote unauthenticated attacker to trigger a software abort via a crafted calendar invite, resulting in denial of service. It was published on December 25, 2025, with a patch available in version 37.2. It carries a CVSS v3.1 base score of 5.9 (Medium) (Pexip Security Bulletins, Red Hat CVE).

Technical details

The root cause is a reachable assertion (CWE-617) in the OTJ service's input validation logic, which fails to properly sanitize or validate incoming calendar invite data when OTJ for Teams SIP Guest Join is enabled. An attacker can send a specially crafted calendar invite over the network, causing the OTJ service to hit an internal assertion and abort, disrupting service availability. Exploitation requires high attack complexity (AC:H), no privileges, and no user interaction, suggesting the crafted input must meet specific conditions to trigger the abort. No public proof-of-concept or technical write-up detailing the exact payload structure has been identified (Pexip Security Bulletins, Red Hat CVE).

Impact

Successful exploitation results in a denial of service by causing the OTJ service to abort, disrupting video conferencing and collaboration capabilities for organizations relying on Pexip Infinity's Teams SIP Guest Join integration. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the vulnerable OTJ service component on systems where the specific configuration is enabled (Pexip Security Bulletins).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.139%, reflecting a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Red Hat CVE, ENISA EUVD).

Mitigation and workarounds

Pexip has released version 37.2 of Pexip Infinity, which addresses this vulnerability. Organizations running versions 32.0 through 37.1 should upgrade to 37.2 or later as the primary remediation. As an interim workaround for systems that cannot be immediately patched, consider disabling OTJ for Teams SIP Guest Join functionality or implementing network-level controls to restrict calendar invite processing to trusted sources (Pexip Security Bulletins).

Additional resources


Source: This report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103110CRITICAL9.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103109CRITICAL9.4
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103105HIGH8.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103106HIGH7.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103108HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management