CVE-2026-103105
Received Received - Intake

Improper Access Control in Pexip Infinity

Vulnerability report for CVE-2026-103105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pexip infinity to 38.2 (exc)
pexip infinity 39.0
pexip infinity 39.1
pexip infinity 40.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control issue in Pexip Infinity versions before 38.2, plus 39.0, 39.1, and 40.0. It allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another node.

Detection Guidance

Detection requires checking Pexip Infinity versions for affected releases (before 38.2, 39.0, 39.1, 40.0). Inspect system logs for unusual API access patterns or unprivileged user activity across nodes. No specific commands are provided in the context.

Impact Analysis

An attacker could gain unauthorized access to other nodes in the Pexip Infinity installation, potentially leading to data breaches, system compromise, or disruption of services. This could affect confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Update Pexip Infinity to a version that is not affected by this vulnerability, specifically versions after 40.0. If local access is a concern, restrict physical and remote access to nodes within the installation to prevent unauthorized use of the vulnerable API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart