Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://docs.pexip.com/admin/security_bulletins.htm |
|
Wed, 30 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system. | |
| First Time appeared |
Pexip
Pexip infinity |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pexip
Pexip infinity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-30T02:45:39.257Z
Reserved: 2026-09-30T02:45:38.445Z
Link: CVE-2026-103106
No data.
Status : Received
Published: 2026-09-30T03:16:59.773
Modified: 2026-09-30T03:16:59.773
Link: CVE-2026-103106
No data.
OpenCVE Enrichment
No data.
