
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66377 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Pexip Infinity's product-internal API, affecting all versions before 39.0. An attacker who has already achieved code execution on one node within a Pexip Infinity installation can exploit this flaw to impact the operation of other nodes in the same deployment. The vulnerability was published on December 25, 2025, with a patch available in version 39.0. It carries a CVSS v3.1 base score of 7.5 (High) (Pexip Security Bulletins, Red Hat CVE).
The root cause is CWE-306 (Missing Authentication for Critical Function): a product-internal API within Pexip Infinity does not enforce authentication, allowing any party with code execution on one node to interact with that API and affect other nodes in the cluster. The attack vector is adjacent network (AV:A), meaning the attacker must already have a foothold — specifically code execution — on at least one node within the Pexip Infinity installation. Attack complexity is rated High (AC:H), reflecting the prerequisite of prior node compromise. No public proof-of-concept exploit code has been identified at this time (Pexip Security Bulletins, Red Hat CVE).
Successful exploitation allows an attacker who has compromised one node to laterally impact other nodes within the same Pexip Infinity installation, with high confidentiality, integrity, and availability impacts. This could result in disruption of video conferencing services, unauthorized access to call data or media streams, and manipulation of node configurations across the deployment. The scope is limited to the Pexip Infinity installation itself (S:U), but the potential for cross-node compromise makes this a significant risk in multi-node enterprise deployments (Pexip Security Bulletins, Red Hat CVE).
Pexip has released version 39.0 of Pexip Infinity, which addresses this vulnerability. Organizations should upgrade all nodes in their Pexip Infinity installation to version 39.0 or later as the primary remediation. As a network-level workaround, restrict access to inter-node management interfaces using firewall rules or network segmentation to limit exposure of internal APIs to trusted nodes only. Monitor for anomalous inter-node API activity as a compensating control until patching is complete (Pexip Security Bulletins).
The vulnerability received coverage from security news aggregators including The Hacker Wire and was noted in CISA's weekly vulnerability bulletin (SB25-363) for the week of December 22, 2025. Social media discussion was limited, with brief mentions on Mastodon and Bluesky by security news accounts. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified (CISA Bulletin, The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."