← Vulnerability feed

Vulnerability record · CVE-2019-25066 · published 9 June 2022

CVE-2019-25066: Ajenti improper privilege management vulnerability

Ajenti · Ajenti

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.

8.8 CVSS 3.1 High EPSS 5.4% · top 7.6% CWE-269 · Improper privilege managementCWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 6.5
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/ajenti/ajenti/commit/7aa146b724e0e20cfee2c71ca78fafbf53a8767c PatchThird Party Advisory
https://vuldb.com/?id.143950 ExploitPatchThird Party Advisory
https://www.exploit-db.com/exploits/47497 ExploitPatchThird Party AdvisoryVDB Entry
https://github.com/ajenti/ajenti/commit/7aa146b724e0e20cfee2c71ca78fafbf53a8767c PatchThird Party Advisory
https://vuldb.com/?id.143950 ExploitPatchThird Party Advisory
https://www.exploit-db.com/exploits/47497 ExploitPatchThird Party AdvisoryVDB Entry

Track CVE-2019-25066 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-1000082Ajenti cross-site request forgery vulnerabilityAjenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the serv…EPSS 1.3%8.1CVE-2026-27975Ajenti improper access control vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…EPSS 0.67%7.5CVE-2018-1000126Ajenti information exposure vulnerabilityAjenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as we…EPSS 1.6%7.5CVE-2018-1000081Ajenti improper input validation vulnerabilityAjenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This a…EPSS 1.1%7.2CVE-2026-35175Ajenti missing authorization vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul…EPSS 0.38%6.5CVE-2018-1000080Ajenti incorrect permission assignment vulnerabilityAjenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a …EPSS 0.84%5.3CVE-2018-1000083Ajenti path traversal vulnerabilityAjenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of th…EPSS 1.5%4.3CVE-2014-4301Ajenti cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2019-25066), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.