Sceawere

Vulnerability Detail

CVE-2026-103105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Internal API Exploitation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-30T03:16:59.623Z",
  "pubdate": "2026-09-30T03:16:59.623Z",
  "executiveSummary": "Pexip Infinity versions prior to 38.2, 39.0, 39.1, and 40.0 contain a critical vulnerability characterized by improper access control within a product-internal API.\nThe vulnerability allows an attacker who has achieved local access to a specific node within a Pexip Infinity cluster to execute arbitrary code on a remote node within the same installation.\nThis flaw effectively bypasses horizontal isolation between nodes, permitting lateral movement or unauthorized command execution with the privileges of an unprivileged user.\nThe risk implication is significant for multi-node deployments, as a compromised secondary node can be leveraged to escalate control over the broader infrastructure.\nSuccessful exploitation requires initial local access to at least one node, after which the attacker can interact with the internal API to trigger operations on other targets.\nThis vulnerability highlights a failure in inter-node authentication and authorization mechanisms, where trusted communication channels do not adequately verify the source or authorization of API requests.",
  "technicalDetails": "The core of the vulnerability resides in the insufficient validation and access control enforcement of a product-internal API utilized for inter-node management and orchestration within Pexip Infinity.\nThe internal API architecture relies on a trust model where requests originating from internal components or adjacent nodes are treated with higher implicit trust than external traffic.\nThe vulnerability manifests when an attacker, having gained local shell or command execution capabilities on one Pexip Infinity node, leverages these elevated positions to craft malformed or unauthorized requests directed at the internal API endpoints.\nBecause the internal API fails to verify the cryptographical integrity or the originating identity of the request across nodes, it processes these malicious inputs as legitimate management tasks.\nThe attack flow proceeds as follows: First, the attacker exploits an existing local vulnerability or misconfiguration to gain initial access to an arbitrary node. Second, the attacker performs reconnaissance to identify internal communication pathways utilized by the Pexip Infinity nodes. Third, the attacker initiates requests to the internal API that trigger remote code execution routines intended for legitimate administrative purposes. Finally, the API on the target node processes the unauthorized instruction, executing the attacker-supplied payload under the context of an unprivileged service account.\nThe exploitation does not require the attacker to possess elevated administrative credentials; however, it necessitates the ability to execute system-level instructions on the local node to initiate the API calls.\nAffected versions include Pexip Infinity before 38.2, and specific releases 39.0, 39.1, and 40.0. The vulnerability demonstrates a failure in the 'Defense in Depth' strategy regarding internal network service trust.\nPost-exploitation, the impact involves the potential for persistent code execution across multiple nodes in the cluster, facilitating data exfiltration, service disruption, or further exploitation of underlying system services. The lack of stringent access control checks on these internal API interfaces effectively grants local attackers the capability to orchestrate remote operations that should be strictly gated by node-level authentication and authorization policies."
}
CVE-2026-103105: Pexip Infinity Internal API Exploitation (HIGH Severity, CVSS: 8.8) | Sceawere