CVE-2026-38979 is a clickjacking vulnerability in ajenti through v2.2.13, affecting the browser-facing login and administrative UI. The vulnerability is caused by the lack of anti-framing protections in the ajenti-core/aj/http.py file. The core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding [truncated]
CVE-2026-35175 is a high-severity vulnerability in Ajenti, a Linux and BSD modular server admin panel. An authenticated user with the auth_users plugin could install custom packages without being a superuser. This issue is fixed in version 2.2.15. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. System administrators using Ajenti for server management should prioritize updating to vers [truncated]