Tag
#Pexip Infinity
Understanding and Defending Against CVE-2026-103105: Improper Access Control in Pexip Infinity
CVE-2026-103105 is a high-severity vulnerability affecting Pexip Infinity versions before 38.2, 39.0, 39.1, and 40.0. It allows an attacker with local access to execute arbitrary code as an unprivileged user on another node within the Pexip Infinity installation. This vulnerability has a CVSS score of 8.8, indicating a high level of severity. Understanding the root cause, attack surface, and exploitation mechanics is crucial for defenders to implement effective mitigations.
Critical Remote Code Execution Vulnerability in Pexip Infinity
A critical vulnerability, CVE-2026-103110, with a CVSS score of 9.8, affects Pexip Infinity versions before 38.2, 39.0, 39.1, and 40.0. This vulnerability allows a remote attacker to execute code as an unprivileged user on a Pexip Infinity Conferencing Node due to improper input validation. Organizations are strongly advised to upgrade to a patched version immediately to prevent potential remote code execution attacks.