CVE-2026-40178: ajenti.plugin.core has a race conditions in 2FA
Impact
If the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication.
Patches
This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.
Other sources
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40178?
CVE-2026-40178 has a moderate severity due to its potential to bypass two-factor authentication shortly after a user is authenticated.
How do I fix CVE-2026-40178?
To fix CVE-2026-40178, upgrade to ajenti.plugin.core version 0.112 or later as soon as possible.
What software is affected by CVE-2026-40178?
CVE-2026-40178 affects ajenti.plugin.core versions up to and including 0.111.
What is the impact of CVE-2026-40178?
The impact of CVE-2026-40178 includes the possibility of bypassing two-factor authentication shortly after a user logs in.
When was CVE-2026-40178 disclosed?
CVE-2026-40178 was disclosed on a date not specified in the provided information.