CVE-2026-27975: Ajenti has a potential Remote Code Execution
Published Feb 26, 2026
·Updated
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.
Affected Software
2 affected components
Ajenti Ajenti<2.2.13
Ajenti Ajenti<2.2.13
Remediation
Event History
Feb 26, 2026
CVE Published
via MITRE·02:39 AM
Data Sourced
via MITRE·02:39 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 27, 58142
Event
via FIRST·08:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-27975?
CVE-2026-27975 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-27975?
To fix CVE-2026-27975, upgrade Ajenti to version 2.2.13 or later.
3
Who is affected by CVE-2026-27975?
CVE-2026-27975 affects all versions of Ajenti prior to 2.2.13.
4
What can an attacker do with CVE-2026-27975?
An attacker exploiting CVE-2026-27975 can execute arbitrary code on the affected server.
5
Is CVE-2026-27975 remote or local?
CVE-2026-27975 is a remote vulnerability, allowing unauthenticated users to exploit it from outside the server.