Description
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.
Published: 2026-09-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to root
Action: Immediate Patch
AI Analysis

Impact

Pexip Infinity contains an improper input validation flaw in an internal service that allows an attacker with local access to elevate privileges to the root user. This vulnerability is rated with a CVSS score of 7.8, reflecting a high severity impact on system integrity and confidentiality. Exploitation requires the attacker to already execute code on the node, either through remote code execution via another flaw or by possessing administrative access to the operating system.

Affected Systems

The flaw affects Pexip Infinity versions prior to 38.2, as well as 39.0, 39.1, and 40.0. Users running these releases should verify their installation and plan an update.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attacks would necessitate local or OS‑level access, limiting the threat to environments where non‑privileged users can run arbitrary code. Despite the high CVSS, the lack of a public exploit and required access reduces immediate risk, but patching remains advisable.

Generated by OpenCVE AI on September 30, 2026 at 07:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to a release that is not listed as affected, such as version 40.1 or later.
  • If an upgrade cannot be performed immediately, limit local user permissions and isolate the internal service from untrusted networks.
  • Monitor system logs for attempts to run code with elevated privileges and configure alerts for root or root‑level process creation.

Generated by OpenCVE AI on September 30, 2026 at 07:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation through Improper Input Validation in Pexip Infinity

Wed, 30 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-669
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T02:45:39.257Z

Reserved: 2026-09-30T02:45:38.445Z

Link: CVE-2026-103106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T03:16:59.773

Modified: 2026-09-30T16:44:39.840

Link: CVE-2026-103106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres