CVE-2026-35175: Ajenti has an authorization bypass during custom package installation
Published Apr 3, 2026
·Updated
Impact
An authenticated user (using the authusers plugin authentication method) could install a custom package even if this user is not superuser.
Patches
This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.
Other sources
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the authusers plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.
— MITRE
Affected Software
2 affected componentsFixes available
pip/ajenti-panel<2.2.15
2.2.15
Ajenti Ajenti<2.2.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/ajenti-panelto a version that resolves this vulnerability.Fixed in 2.2.15 - Upgrade
Upgrade
Ajentito a version that resolves this vulnerability.Fixed in 2.2.15
Event History
Apr 3, 2026
Advisory Published
via GitHub·03:57 AM
Data Sourced
via GitHub·03:57 AM
DescriptionWeaknessAffected Software
Apr 6, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
RemedyAffected Software