CVE-2026-40177Disclosure(ajenti / ajenti_plugin_core)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ajenti ajenti_plugin_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ajenti_plugin_core

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-10); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
ajenti_plugin_core

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-10: 3Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 104-1004-1104-1304-15
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure2General1
2026-04-111
Disclosure1
2026-04-131
Disclosure1
2026-04-151
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    General

    CVE-2026-40177 ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the passwo… https://www.cve.org/CVERecord?id=CVE-2026-40177

    Post summary

    The text references CVE-2026-40177 as a 2FA bypass vulnerability in Ajenti’s core plugin, citing the CVE record link but offering no details on exploitation, tool, or patch.

    00010188
    57.0K followersView on X
  • Daily Security Review@securitydailyr
    Disclosure

    Two critical command injection vulnerabilities, CVE-2026-40176 and CVE-2026-40177, have been found in Composer’s Perforce VCS driver—putting countless PHP applications at risk. Learn more: https://dailysecurityreview.com/resources/critical-security-flaws-in-composer-put-php-applications-at-risk/ https://t.co/9zivfP1lZf

    Post summary

    The post announces the discovery of two critical command injection CVEs (CVE-2026-40176 and CVE-2026-40177) affecting Composer’s Perforce VCS driver, warning that many PHP applications are at risk.

    0000038
    110 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Authentication Bypass (#AuthB) in #Ajenti Core plugin. CVE-2026-40177 CVSS(4.0): 9.3. If 2FA is activated, it's possible to bypass password authentication. https://github.com/ajenti/ajenti/security/advisories/GHSA-3mcx-6wxm-qr8v #Patch #Patch #Patch

    Post summary

    The statement announces a critical authentication bypass vulnerability (CVE-2026-40177) in Ajenti Core, supplying its CVSS score and linking to a GitHub security advisory.

    00000173
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical 2FA bypass (CVE-2026-40177) affects `ajenti.plugin.core`. Attackers can gain unauthorized access despite 2FA being active. Admins should review `ajenti` deployments and prepare for patches. #infosec #ajenti #cybersecurity https://www.pulsepatch.io/posts/cve-2026-40177-ajenti-plugin-core-2fa-bypass

    Post summary

    A critical 2FA bypass vulnerability (CVE-2026-40177) in ajenti.plugin.core has been disclosed, with administrators urged to review deployments and prepare for forthcoming patches; no proof of concept or active exploitation details are provided.

    0000060
    11 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40177 Authentication Bypass in Ajenti Plugin Core Versions Prior to 0.112 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40177

    Post summary

    The text announces CVE-2026-40177 as an authentication bypass flaw affecting Ajenti Plugin Core versions earlier than 0.112, with no PoC, exploitation, or patch details provided.

    0000041
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40177: Password bypass when 2FA is acti... Ajenti's 2FA implementation fails catastrophically - attackers can skip password auth entirely when MFA is enabled, tur... https://zerodaysignal.com/vulnerability/CVE-2026-40177 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑40177, noting a critical 2FA bypass in Ajenti that allows password skipping when MFA is enabled, without detailing PoCs, exploits, or fixes.

    0000073
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appajentiajenti_plugin_core---

Explore more