OVERVIEW CVE-2026-35175 affects Ajenti, a modular server administration panel for Linux and BSD systems, in versions prior to 2.2.15. The vulnerability allows authenticated users with standard user privileges (those using auth_users plugin authentication) to install custom packages without requiring superuser permissions, effectively bypassing access controls intended to restrict this administrative function. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM) with a network-accessible attack vector requiring low complexity and valid user credentials. While the attack does not compromise confidentiality or system availability, it poses a significant integrity risk by allowing unauthorized package installation. The FAUCET Risk Score of 35.0/100 reflects moderate concern within the threat landscape. EXPLOITATION STATUS This vulnerability currently shows minimal real-world exploitation activity. It does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, the community hot list is inactive, and the EPSS score of 0.00016 indicates extremely low probability of exploitation in the wild. However, organizations running Ajenti versions prior to 2.2.15 should prioritize patching to eliminate this privilege escalation pathway.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.15CPE matchmatch criteria | cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.