← Vulnerability feed

Vulnerability record · CVE-2026-27975 · published 26 February 2026

CVE-2026-27975: Ajenti improper access control vulnerability

Ajenti · Ajenti

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.

8.1 CVSS 4.0 High EPSS 0.67% · top 50.2% CWE-284 · Improper access control
8.1CVSS 4.0 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-25066Ajenti improper privilege management vulnerabilityA vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul…EPSS 5.4%8.8CVE-2018-1000082Ajenti cross-site request forgery vulnerabilityAjenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the serv…EPSS 1.3%7.5CVE-2018-1000126Ajenti information exposure vulnerabilityAjenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as we…EPSS 1.6%7.5CVE-2018-1000081Ajenti improper input validation vulnerabilityAjenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This a…EPSS 1.1%7.2CVE-2026-35175Ajenti missing authorization vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul…EPSS 0.38%6.5CVE-2018-1000080Ajenti incorrect permission assignment vulnerabilityAjenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a …EPSS 0.84%5.3CVE-2018-1000083Ajenti path traversal vulnerabilityAjenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of th…EPSS 1.5%4.3CVE-2014-4301Ajenti cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2026-27975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.