Clickjacking Vulnerability in Ajenti's Administrative Interface
CVE-2026-38979

5.4MEDIUM

Key Information:

Vendor

Ajenti

Vendor
CVE Published:
6 July 2026

What is CVE-2026-38979?

Ajenti version 2.2.13 is susceptible to a clickjacking vulnerability within its browser-based login and administrative UI. The vulnerability arises from the lack of critical anti-framing protections, such as the X-Frame-Options header and the Content-Security-Policy frame-ancestors directive. These omissions allow malicious actors to potentially craft deceptive frames, tricking users into unknowingly interacting with the application's interface in harmful ways, further jeopardizing user security and data integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.