Clickjacking Vulnerability in Ajenti's Administrative Interface
CVE-2026-38979
5.4MEDIUM
What is CVE-2026-38979?
Ajenti version 2.2.13 is susceptible to a clickjacking vulnerability within its browser-based login and administrative UI. The vulnerability arises from the lack of critical anti-framing protections, such as the X-Frame-Options header and the Content-Security-Policy frame-ancestors directive. These omissions allow malicious actors to potentially craft deceptive frames, tricking users into unknowingly interacting with the application's interface in harmful ways, further jeopardizing user security and data integrity.
