{"id":"CVE-2026-35175","aliases":["GHSA-73jv-44c3-j5p2","PYSEC-2026-2339"],"title":"Ajenti has an authorization bypass during custom package installation","summary":"Ajenti has an authorization bypass during custom package installation","severity":"high","vendor":"ajenti-panel","product":"ajenti-panel","ecosystem":"pip","affected":["ajenti-panel < 2.2.15"],"patched":["ajenti-panel 2.2.15"],"published":"2026-04-03","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-73jv-44c3-j5p2","references":[{"url":"https://github.com/ajenti/ajenti/security/advisories/GHSA-73jv-44c3-j5p2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35175"},{"url":"https://github.com/ajenti/ajenti"},{"url":"https://github.com/ajenti/ajenti/releases/tag/v2.2.15"}],"tags":["osv","pip"],"epss":0.00266,"epssPercentile":0.18794,"ingestedAt":"2026-07-13T18:57:54.111Z","slug":"CVE-2026-35175","body":"## Overview\n\n### Impact\n\nAn authenticated user (using the `auth_users` plugin authentication method) could install a custom package even if this user is not superuser.\n\n### Patches\n\nThis is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.\n\n## Affected packages\n\n- `ajenti-panel < 2.2.15`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `ajenti-panel 2.2.15`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}