{"id":"CVE-2026-40178","aliases":["GHSA-8647-755q-fw9p","PYSEC-2026-2340"],"title":"ajenti.plugin.core has race conditions in 2FA","summary":"ajenti.plugin.core has race conditions in 2FA","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","vendor":"ajenti-plugin-core","product":"ajenti-plugin-core","ecosystem":"pip","affected":["ajenti-plugin-core < 0.112"],"patched":["ajenti-plugin-core 0.112"],"published":"2026-04-10","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8647-755q-fw9p","references":[{"url":"https://github.com/ajenti/ajenti/security/advisories/GHSA-8647-755q-fw9p"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40178"},{"url":"https://github.com/ajenti/ajenti"}],"tags":["osv","pip"],"epss":0.00232,"epssPercentile":0.14401,"ingestedAt":"2026-07-13T18:57:54.852Z","slug":"CVE-2026-40178","body":"## Overview\n\n### Impact\n\nIf the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication.\n\n### Patches\n\nThis is fixed in the version 0.112. Users should upgrade to this version as soon as possible.\n\n## Affected packages\n\n- `ajenti-plugin-core < 0.112`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `ajenti-plugin-core 0.112`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}