
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103105 is an improper access control vulnerability (CWE-863: Incorrect Authorization) affecting Pexip Infinity's product-internal API. It allows an attacker with local access to one node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another node in the same deployment. Affected versions include all releases before 38.2, as well as versions 39.0, 39.1, and 40.0. The vulnerability was published on September 30, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Pexip Security Bulletins).
The root cause is incorrect authorization (CWE-863) on a product-internal API used for inter-node communication within a Pexip Infinity cluster. Because the API does not properly enforce access controls, an attacker who has already gained local access to one node can send crafted requests to this internal API and trigger arbitrary code execution on adjacent nodes — without requiring any privileges or user interaction. The attack vector is adjacent network (AV:A), meaning the attacker must be on the same network segment or have local node access, but no authentication is required to exploit the vulnerable API endpoint (GitHub Advisory, Pexip Security Bulletins).
Successful exploitation results in arbitrary code execution on a remote Pexip Infinity node, with high impact to confidentiality, integrity, and availability. An attacker who compromises one node in a Pexip Infinity cluster can leverage this vulnerability to laterally move to other nodes within the same installation, potentially compromising the entire video conferencing infrastructure. Sensitive communications data, configuration, and credentials stored on affected nodes may be exposed or tampered with (GitHub Advisory, Pexip Security Bulletins).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.184% (7th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to first obtain local access to a node within the Pexip Infinity installation, which limits opportunistic exploitation but does not eliminate risk in targeted attack scenarios.
Pexip has released patches addressing this vulnerability. Organizations should upgrade Pexip Infinity to version 38.2 or later; versions 39.0, 39.1, and 40.0 are also vulnerable and must be upgraded to a fixed release. As interim mitigations, restrict local and administrative access to Pexip Infinity nodes to authorized personnel only, and implement network segmentation to limit adjacent network access between nodes within the installation (Pexip Security Bulletins, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."