CVE-2026-35175High▾ TwilightAjenti has an authorization bypass during custom package installation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
An authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser.
This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.
ajenti-panel < 2.2.15Upgrade to a patched release:
ajenti-panel 2.2.15