Description
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8647-755q-fw9p | ajenti.plugin.core has race conditions in 2FA |
References
History
Fri, 10 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112. | |
| Title | ajenti.plugin.core has a race conditions in 2FA | |
| Weaknesses | CWE-287 CWE-362 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-10T19:30:47.083Z
Reserved: 2026-04-09T20:59:17.619Z
Link: CVE-2026-40178
No data.
Status : Received
Published: 2026-04-10T20:16:23.117
Modified: 2026-04-10T20:16:23.117
Link: CVE-2026-40178
No data.
OpenCVE Enrichment
No data.
Github GHSA