Improper Access Control in Ajenti Server Admin Panel
CVE-2026-35175
7.2HIGH
What is CVE-2026-35175?
Ajenti is a modular server administration panel for Linux and BSD systems. Versions prior to 2.2.15 contain an access control vulnerability that allows authenticated users, utilizing the auth_users plugin method, to install custom packages without requiring superuser privileges. This oversight can lead to unauthorized modifications within the system, making it crucial for affected users to upgrade to version 2.2.15 or later to mitigate potential security risks.
Affected Version(s)
ajenti < 2.2.15
