Improper Access Control in Ajenti Server Admin Panel
CVE-2026-35175

7.2HIGH

Key Information:

Vendor

Ajenti

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35175?

Ajenti is a modular server administration panel for Linux and BSD systems. Versions prior to 2.2.15 contain an access control vulnerability that allows authenticated users, utilizing the auth_users plugin method, to install custom packages without requiring superuser privileges. This oversight can lead to unauthorized modifications within the system, making it crucial for affected users to upgrade to version 2.2.15 or later to mitigate potential security risks.

Affected Version(s)

ajenti < 2.2.15

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.