Ajenti is a modestly represented, server-management and system-administration platform whose vulnerability footprint, despite a narrow product scope, ranks among more prominent vendors in the landscape. Vulnerabilities affecting the platform cluster around web-application and authentication-layer weaknesses—cross-site scripting, improper authentication, race conditions, and cross-site request forgery—that are characteristic of remotely accessible administration interfaces, and frequently acquire public exploit code. A meaningful share of the vendor's disclosures reach critical severity, reflecting the elevated privilege and broad system access that these vulnerabilities can confer on an attacker. Defenders should treat Ajenti instances, particularly internet-facing or exposed administrative panels, as high-priority patching targets; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ajenti over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25066HIGH A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escala | Jun 9, 2022 | 8.8 | 40 | NO | YES |
CVE-2026-27975CRITICAL Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This | Feb 26, 2026 | 9.8 | 32 | NO | NO |
CVE-2018-18548MEDIUM ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager. | Oct 24, 2018 | 6.1 | 32 | NO | YES |
CVE-2026-40177HIGH ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authenticat | Apr 10, 2026 | 7.5 | 27 | NO | NO |
CVE-2018-1000082HIGH Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code exe | Mar 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2026-40178MEDIUM ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the au | Apr 10, 2026 | 5.9 | 22 | NO | NO |
CVE-2026-35175MEDIUM Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even | Apr 6, 2026 | 6.5 | 22 | NO | NO |
CVE-2018-1000126HIGH Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti | Mar 13, 2018 | 7.5 | 22 | NO | NO |
CVE-2018-1000081HIGH Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable | Mar 13, 2018 | 7.5 | 22 | NO | NO |
CVE-2018-1000080MEDIUM Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear | Mar 13, 2018 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ajenti.
Media articles that mention a CVE ID that affects a product developed by Ajenti — matched by CVE ID, not by vendor name.