Impact
Pexip Infinity contains an improper input validation flaw in an internal service that allows an attacker with local access to elevate privileges to the root user. This vulnerability is rated with a CVSS score of 7.8, reflecting a high severity impact on system integrity and confidentiality. Exploitation requires the attacker to already execute code on the node, either through remote code execution via another flaw or by possessing administrative access to the operating system.
Affected Systems
The flaw affects Pexip Infinity versions prior to 38.2, as well as 39.0, 39.1, and 40.0. Users running these releases should verify their installation and plan an update.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attacks would necessitate local or OS‑level access, limiting the threat to environments where non‑privileged users can run arbitrary code. Despite the high CVSS, the lack of a public exploit and required access reduces immediate risk, but patching remains advisable.
OpenCVE Enrichment