
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35175 is an authorization bypass vulnerability in Ajenti, an open-source web-based server administration panel, that allows authenticated non-superuser accounts to install custom packages without proper privilege checks. It affects all versions of the ajenti-panel pip package prior to 2.2.15 and is classified as CWE-862 (Missing Authorization). The vulnerability was published on April 1, 2026, by researcher Thien225409 and added to the GitHub Advisory Database on April 3, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, Ajenti Advisory).
The root cause is a missing authorization check (CWE-862) in Ajenti's package installation functionality when the auth_users plugin is used as the authentication method. The application fails to verify whether the authenticated user holds superuser privileges before permitting the installation of custom packages, allowing any valid user account to perform a privileged administrative action. The attack is network-based, requires only low-level authenticated access, and involves no user interaction, making it straightforward to exploit once credentials are obtained (GitHub Advisory, Ajenti Advisory).
Successful exploitation allows a low-privileged authenticated user to install arbitrary custom packages on the server managed by Ajenti, resulting in a high integrity impact on the vulnerable system. This could enable an attacker to introduce malicious software, backdoors, or unauthorized system modifications, potentially leading to full server compromise or lateral movement within the environment. Confidentiality and availability impacts are rated low to moderate under CVSS v4.0, reflecting secondary risks from installed malicious packages (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.061% (0.023% per GitHub Advisory), placing it in the 7th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials for an Ajenti instance using the auth_users authentication plugin, limiting the attack surface to authenticated users (GitHub Advisory).
auth_users authentication plugin enabled.The vulnerability is fixed in Ajenti version 2.2.15, released March 31, 2026. Users should upgrade the ajenti-panel pip package to version 2.2.15 or later as soon as possible. As a temporary workaround, administrators can restrict Ajenti access to trusted users only, avoid using the auth_users plugin with untrusted accounts, or limit network access to the Ajenti panel via firewall rules until the upgrade can be applied (GitHub Advisory, Ajenti Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."