PatchSiren cyber security CVE debrief
CVE-2026-35175 ajenti CVE debrief
CVE-2026-35175 is a high-severity vulnerability in Ajenti, a Linux and BSD modular server admin panel. An authenticated user with the auth_users plugin could install custom packages without being a superuser. This issue is fixed in version 2.2.15. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. System administrators using Ajenti for server management should prioritize updating to version 2.2.15 or later to prevent potential unauthorized package installations. The vulnerability allows authenticated users to install custom packages, which could lead to unauthorized changes on the server.
- Vendor
- ajenti
- Product
- Unknown
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
System administrators using Ajenti for server management should prioritize updating to version 2.2.15 or later to prevent potential unauthorized package installations. This includes administrators who manage Linux and BSD systems. The vulnerability affects users with the auth_users plugin. System administrators should review user permissions and ensure that only authorized users can install packages.
Technical summary
CVE-2026-35175 allows authenticated users with the auth_users plugin to install custom packages in Ajenti versions prior to 2.2.15. This could lead to unauthorized changes on the server. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. The issue is addressed in Ajenti version 2.2.15. System administrators should ensure that only authorized personnel have the ability to install packages. The vulnerability affects Ajenti versions prior to 2.2.15.
Defensive priority
High priority should be given to updating Ajenti to version 2.2.15 or later. System administrators should ensure that only authorized personnel have the ability to install packages. Additional monitoring and logging should be implemented to detect potential security incidents.
Recommended defensive actions
- Update Ajenti to version 2.2.15 or later
- Review user permissions and ensure that only authorized users can install packages
- Monitor server logs for any suspicious package installation attempts
- Verify the integrity of installed packages
- Conduct regular security audits
- Implement additional monitoring and logging
- Review and update incident response plans
Evidence notes
The CVE record was published on 2026-04-06T18:16:43.830Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects Ajenti versions prior to 2.2.15. The CVE record and NVD entry provide additional context on the vulnerability. Defenders should verify the affected scope and severity using the official advisory.
Official resources
-
CVE-2026-35175 CVE record
CVE.org
-
CVE-2026-35175 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Product, Release Notes
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T18:16:43.830Z and has not been modified since then. The NVD entry is currently Analyzed.