---
id: CVE-2026-103106
title: >-
  Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper
  input validation within an internal Pexip Infinity service that allows an
  attacker with local access to escalate privileges to root
summary: >-
  Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper
  input validation within an internal Pexip Infinity service that allows an
  attacker with local access to escalate privileges to root. Exploitation
  requires an …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-669
vendor: Pexip
product: Infinity
affected:
  - Infinity < 38.2.0
  - Infinity 39.0.0
  - Infinity 39.1.0
  - Infinity 40.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T03:16:59.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103106'
references:
  - url: 'https://docs.pexip.com/admin/security_bulletins.htm'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T03:56:19.554Z'
---

## Overview

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
