Sceawere
Vulnerability Detail
CVE-2026-103105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pexip Infinity Internal API Exploitation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 4h ago
- Vendor
- Pexip
- Product
- Infinity
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-30T03:16:59.623Z",
"pubdate": "2026-09-30T03:16:59.623Z",
"executiveSummary": "Pexip Infinity versions prior to 38.2, 39.0, 39.1, and 40.0 contain a critical vulnerability characterized by improper access control within a product-internal API.\nThe vulnerability allows an attacker who has achieved local access to a specific node within a Pexip Infinity cluster to execute arbitrary code on a remote node within the same installation.\nThis flaw effectively bypasses horizontal isolation between nodes, permitting lateral movement or unauthorized command execution with the privileges of an unprivileged user.\nThe risk implication is significant for multi-node deployments, as a compromised secondary node can be leveraged to escalate control over the broader infrastructure.\nSuccessful exploitation requires initial local access to at least one node, after which the attacker can interact with the internal API to trigger operations on other targets.\nThis vulnerability highlights a failure in inter-node authentication and authorization mechanisms, where trusted communication channels do not adequately verify the source or authorization of API requests.",
"technicalDetails": "The core of the vulnerability resides in the insufficient validation and access control enforcement of a product-internal API utilized for inter-node management and orchestration within Pexip Infinity.\nThe internal API architecture relies on a trust model where requests originating from internal components or adjacent nodes are treated with higher implicit trust than external traffic.\nThe vulnerability manifests when an attacker, having gained local shell or command execution capabilities on one Pexip Infinity node, leverages these elevated positions to craft malformed or unauthorized requests directed at the internal API endpoints.\nBecause the internal API fails to verify the cryptographical integrity or the originating identity of the request across nodes, it processes these malicious inputs as legitimate management tasks.\nThe attack flow proceeds as follows: First, the attacker exploits an existing local vulnerability or misconfiguration to gain initial access to an arbitrary node. Second, the attacker performs reconnaissance to identify internal communication pathways utilized by the Pexip Infinity nodes. Third, the attacker initiates requests to the internal API that trigger remote code execution routines intended for legitimate administrative purposes. Finally, the API on the target node processes the unauthorized instruction, executing the attacker-supplied payload under the context of an unprivileged service account.\nThe exploitation does not require the attacker to possess elevated administrative credentials; however, it necessitates the ability to execute system-level instructions on the local node to initiate the API calls.\nAffected versions include Pexip Infinity before 38.2, and specific releases 39.0, 39.1, and 40.0. The vulnerability demonstrates a failure in the 'Defense in Depth' strategy regarding internal network service trust.\nPost-exploitation, the impact involves the potential for persistent code execution across multiple nodes in the cluster, facilitating data exfiltration, service disruption, or further exploitation of underlying system services. The lack of stringent access control checks on these internal API interfaces effectively grants local attackers the capability to orchestrate remote operations that should be strictly gated by node-level authentication and authorization policies."
}