High severity7.5NVD Advisory· Published Apr 10, 2026· Updated Apr 21, 2026
CVE-2026-40177
CVE-2026-40177
Description
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ajenti.plugin.corePyPI | < 0.112 | 0.112 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-3mcx-6wxm-qr8vghsaADVISORY
- github.com/ajenti/ajenti/security/advisories/GHSA-3mcx-6wxm-qr8vnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-40177ghsaADVISORY
News mentions
0No linked articles in our index yet.