
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103106 is a local privilege escalation vulnerability in Pexip Infinity caused by improper input validation within an internal Pexip Infinity service. It affects Pexip Infinity versions before 38.2, as well as versions 39.0, 39.1, and 40.0. An attacker with local code execution capability can exploit this flaw to escalate privileges to root. It was published on September 30, 2026, with a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Pexip Security Bulletins).
The vulnerability is classified as CWE-669 (Incorrect Resource Transfer Between Spheres), meaning an internal Pexip Infinity service improperly handles resource or behavior transfers in a way that grants unintended elevated control (GitHub Advisory). Exploitation requires the attacker to already have the ability to execute arbitrary code on a Pexip Infinity node — either through a separate remote code execution vulnerability or by possessing administrative access to the operating system. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once the prerequisite code execution capability is established (GitHub Advisory). No public proof-of-concept code has been identified.
Successful exploitation allows a local attacker to escalate privileges to root on the affected Pexip Infinity node, resulting in complete compromise of confidentiality, integrity, and availability of that node. With root access, an attacker could manipulate conferencing infrastructure, intercept communications, exfiltrate sensitive data, or pivot to other systems within the network. The scope is limited to the compromised node, but the total technical impact is classified as high across all three security pillars (GitHub Advisory, Pexip Security Bulletins).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The EPSS score is approximately 0.141% (3rd percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable due to the prerequisite requirement for local code execution on the target node.
auditd records showing a non-root process gaining root UID); unusual entries in Pexip Infinity service logs indicating malformed or unexpected input to internal services./root/, /etc/) created by Pexip service accounts; unexpected cron jobs, SSH authorized keys, or SUID binaries added post-exploitation.Pexip has released patches addressing this vulnerability; administrators should upgrade Pexip Infinity to version 38.2 or later (for the 38.x branch), and ensure 39.x and 40.x deployments are updated to their respective fixed releases (Pexip Security Bulletins, GitHub Advisory). As interim mitigations, restrict administrative and OS-level access to Pexip Infinity nodes to the minimum necessary personnel, and apply network segmentation to limit access to Pexip infrastructure. Monitor systems for signs of privilege escalation activity using host-based security tools.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."