CVE-2026-103110: Input Validation
Published Sep 30, 2026
·Updated
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
Affected Software
1 affected component
Pexip Infinity<38.2, =39.0, =39.1, =40.0
Event History
Sep 30, 2026
CVE Published
via MITRE·03:03 AM
Data Sourced
via MITRE·03:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Affected releases are Pexip Infinity versions before 38.2, as well as versions 39.0, 39.1, and 40.0. The issue affects Pexip Infinity Conferencing Nodes.
2
Does exploitation require authentication or user interaction?
No. The provided vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction required.
3
What level of access could an attacker obtain?
A remote attacker can execute code as an unprivileged user on an affected Pexip Infinity Conferencing Node. The vulnerability is rated critical and has high impacts on confidentiality, integrity, and availability.