PatchSiren

ajenti CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ajenti CVE published 2026-07-06

CVE-2026-38979

CVE-2026-38979 is a clickjacking vulnerability in ajenti through v2.2.13, affecting the browser-facing login and administrative UI. The vulnerability is caused by the lack of anti-framing protections in the ajenti-core/aj/http.py file. The core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding [truncated]

HIGH ajenti CVE published 2026-04-06

CVE-2026-35175

CVE-2026-35175 is a high-severity vulnerability in Ajenti, a Linux and BSD modular server admin panel. An authenticated user with the auth_users plugin could install custom packages without being a superuser. This issue is fixed in version 2.2.15. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. System administrators using Ajenti for server management should prioritize updating to vers [truncated]