Vulnerability DatabaseCVE-2026-103110

CVE-2026-103110: 
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2026-103110 is a critical remote code execution vulnerability in Pexip Infinity caused by improper input validation (out-of-bounds write) on Conferencing Nodes. It affects all versions before 38.2, as well as versions 39.0, 39.1, and 40.0. An unauthenticated remote attacker can exploit this flaw to execute arbitrary code as an unprivileged user on a Pexip Infinity Conferencing Node. It was published on September 30, 2026, with a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Pexip Security Bulletins).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), where the Pexip Infinity Conferencing Node fails to properly validate input, allowing an attacker to write data beyond the bounds of an intended buffer. This network-accessible flaw requires no authentication, no user interaction, and no special privileges, making it fully automatable. The attack vector is remote over the network with low complexity, and NVD's SSVC assessment confirms the technical impact is "total" (GitHub Advisory, Pexip Security Bulletins).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code as an unprivileged user on a Pexip Infinity Conferencing Node, resulting in high impacts to confidentiality, integrity, and availability. An attacker could access sensitive conference data, disrupt video conferencing services, or use the compromised node as a foothold for lateral movement within the network. Given that Pexip Infinity is commonly deployed in enterprise and government environments, the potential for sensitive communications exposure is significant (GitHub Advisory, Pexip Security Bulletins).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.608%, placing it in the 47th percentile for exploitation probability within 30 days. No threat actor attribution has been reported. However, the zero-authentication requirement and network accessibility make it highly attractive for future weaponization.

Mitigation and workarounds

Pexip has released patches addressing this vulnerability. Organizations should upgrade Pexip Infinity to version 38.2 or later; versions 39.0, 39.1, and 40.0 are also vulnerable and must be updated to their respective patched releases. As an interim measure where immediate patching is not feasible, apply network segmentation to restrict access to Pexip Infinity Conferencing Nodes to trusted networks only. Refer to the official Pexip security bulletins for specific upgrade guidance (Pexip Security Bulletins, GitHub Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article specifically on the CVE-2026-103110 input validation flaw and its remote code execution implications (The Hacker Wire). Community discussion was noted on Reddit's r/pwnhub in a daily CVE brief, and the vulnerability was shared on Bluesky by cybersecurity community accounts. No formal vendor statement beyond the security bulletin has been identified.

Additional resources


Source: This report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103110CRITICAL9.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103109CRITICAL9.4
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103105HIGH8.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103106HIGH7.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103108HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management