Impact
Pexip Infinity versions before 38.2, along with 39.0, 39.1 and 40.0, are affected by an improper access control flaw on a product‑internal API. The flaw permits an attacker who has local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on a separate node in the same installation. The vulnerability is classified as CWE‑863.
Affected Systems
All Pexip Infinity installations running any of the affected software versions—any release before 38.2, or the 39.0, 39.1, and 40.0 release lines—are vulnerable. The flaw targets the internal API used for node‑to‑node communication within a Pexip cluster.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires local access to a node, such as through a compromised local account or via an exposed management interface. Once local access is achieved, an attacker can invoke the unauthenticated internal API to gain code execution rights on a different node.
OpenCVE Enrichment