{"id":"CVE-2026-35175","aliases":["GHSA-73jv-44c3-j5p2","PYSEC-2026-2339"],"url":"https://o3.security/vulnerability/CVE-2026-35175","summary":"Ajenti has an authorization bypass during custom package installation","details":"### Impact\n\nAn authenticated user (using the `auth_users` plugin authentication method) could install a custom package even if this user is not superuser.\n\n### Patches\n\nThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.","published":"2026-04-06T17:51:54.898Z","modified":"2026-08-29T03:45:36.311779557Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ajenti-panel","fixedVersion":"2.2.15"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ajenti/ajenti/releases/tag/v2.2.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35175.json"},{"type":"ADVISORY","url":"https://github.com/ajenti/ajenti/security/advisories/GHSA-73jv-44c3-j5p2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35175"},{"type":"PACKAGE","url":"https://github.com/ajenti/ajenti"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-29T03:45:36.311779557Z"}}