CVE-2026-79920

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes pip while running as root. A low-privileged user can therefore select or manipulate a package installed with root privileges and can install, remove, or upgrade plugins without administrative permission, resulting in root code execution and full host compromise. This issue is fixed in version 2.2.16.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-22: 209-22
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 Ajenti'de CVE-2026-79920 — CVSS 9.9 Kritik Güvenlik Açığı! Ajenti adlı sunucu yönetim panelinin<2.2.16 sürümlerini etkileyen kritik yetkilendirme açığı, düşük yetkili kimliği doğrulanmış kullanıcıların plugin yükleme/kaldırma/güncelleme işlemlerini yetkisiz şekilde başlatmasına izin veriyor. Bu açık nedeniyle işlemler root yetkileriyle gerçekleştirilebiliyor, sunucuda kod çalıştırılabiliyor. Ajenti 2.2.16+ sürümüne mutlaka güncelleme yapın.

    10020232
    2.3K followersView on X
  • VulnTracker@vuln_tracker

    Any logged-in Ajenti user can trigger a pip install running as root (CVSS 9.9). CVE-2026-79920 skips plugin-management authorization entirely. A low-privileged user can queue an install/uninstall/upgrade task, and since pip runs as root on unvalidated package name and version fields, that's a straight path to full host compromise. Fixed in ajenti 2.2.16. Update now. Details: http://vulntracker.io/cves/CVE-2026-79920 #Ajenti #CVE #InfoSec #CyberSecurity #PrivilegeEscalation

    0000065
    759 followersView on X

Explore more