CVE-2026-103106: Input Validation
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Only environments where an attacker can execute arbitrary code on a Pexip Infinity node are exposed. This can result from a separate remote code execution vulnerability or from administrative access to the node's operating system.
Does this vulnerability provide initial remote access to a node?
No. Exploitation requires local access and the ability to run arbitrary code on the node; it is a privilege-escalation issue rather than an initial-access vulnerability.
What is the impact after successful exploitation?
An attacker can escalate privileges to root on the affected node, resulting in high impact to confidentiality, integrity, and availability.
Which releases are affected?
Affected releases are Pexip Infinity before 38.2, as well as versions 39.0, 39.1, and 40.0.