Vulnerability DatabaseCVE-2026-103105

CVE-2026-103105: 
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2026-103105 is an improper access control vulnerability (CWE-863: Incorrect Authorization) affecting Pexip Infinity's product-internal API. It allows an attacker with local access to one node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another node in the same deployment. Affected versions include all releases before 38.2, as well as versions 39.0, 39.1, and 40.0. The vulnerability was published on September 30, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Pexip Security Bulletins).

Technical details

The root cause is incorrect authorization (CWE-863) on a product-internal API used for inter-node communication within a Pexip Infinity cluster. Because the API does not properly enforce access controls, an attacker who has already gained local access to one node can send crafted requests to this internal API and trigger arbitrary code execution on adjacent nodes — without requiring any privileges or user interaction. The attack vector is adjacent network (AV:A), meaning the attacker must be on the same network segment or have local node access, but no authentication is required to exploit the vulnerable API endpoint (GitHub Advisory, Pexip Security Bulletins).

Impact

Successful exploitation results in arbitrary code execution on a remote Pexip Infinity node, with high impact to confidentiality, integrity, and availability. An attacker who compromises one node in a Pexip Infinity cluster can leverage this vulnerability to laterally move to other nodes within the same installation, potentially compromising the entire video conferencing infrastructure. Sensitive communications data, configuration, and credentials stored on affected nodes may be exposed or tampered with (GitHub Advisory, Pexip Security Bulletins).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.184% (7th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to first obtain local access to a node within the Pexip Infinity installation, which limits opportunistic exploitation but does not eliminate risk in targeted attack scenarios.

Mitigation and workarounds

Pexip has released patches addressing this vulnerability. Organizations should upgrade Pexip Infinity to version 38.2 or later; versions 39.0, 39.1, and 40.0 are also vulnerable and must be upgraded to a fixed release. As interim mitigations, restrict local and administrative access to Pexip Infinity nodes to authorized personnel only, and implement network segmentation to limit adjacent network access between nodes within the installation (Pexip Security Bulletins, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103110CRITICAL9.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103109CRITICAL9.4
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103105HIGH8.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103106HIGH7.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103108HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management