CVE-2026-40177: Password bypass when 2FA is activated
Impact
If the 2FA was activated, it was possible to bypass the password authentication
Patches
This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.
Other sources
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40177?
CVE-2026-40177 has a critical severity rating due to the potential for bypassing password authentication when 2FA is enabled.
How do I fix CVE-2026-40177?
To fix CVE-2026-40177, users must upgrade to version 0.112 of the ajenti.plugin.core package as soon as possible.
What type of vulnerability is CVE-2026-40177?
CVE-2026-40177 is a password bypass vulnerability that affects two-factor authentication systems.
Which software is affected by CVE-2026-40177?
CVE-2026-40177 specifically affects versions of the ajenti.plugin.core package prior to 0.112.
Is CVE-2026-40177 being actively exploited?
While there is no specific indication of active exploitation for CVE-2026-40177, its critical nature implies potential risk if not addressed.