Sceawere
Vulnerability Detail
CVE-2026-103106UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pexip Infinity Local Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 4h ago
- Vendor
- Pexip
- Product
- Infinity
- Attack Type
- CWE-669 Incorrect Resource Transfer Between Spheres
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-30T03:16:59.773Z",
"pubdate": "2026-09-30T03:16:59.773Z",
"executiveSummary": "Pexip Infinity is susceptible to a local privilege escalation vulnerability caused by improper input validation within an internal service. This flaw enables an attacker who has already established a foothold on a node to escalate their privileges to root. The vulnerability affects Pexip Infinity versions prior to 38.2, as well as versions 39.0, 39.1, and 40.0. The risk is significant as it facilitates complete system compromise following the initial breach. Exploitation requires the attacker to have pre-existing local access to the operating system or the ability to execute arbitrary code via a separate, secondary exploit. By interacting with the vulnerable internal service, a low-privileged user can manipulate input vectors to gain unauthorized administrative control over the underlying host. Organizations should prioritize patching to remediate the vulnerable component and limit potential lateral movement or system-level compromise.",
"technicalDetails": "The vulnerability originates from improper input validation logic residing within an internal service component of Pexip Infinity. This service, which operates with elevated privileges, fails to adequately sanitize or constrain inputs provided by local processes. The architectural flaw allows a process executing with limited user-level permissions to interact with the service in a manner that triggers an unintended execution path or memory manipulation, resulting in privilege escalation.\nThe attack flow requires an adversary to first establish execution capability on the target node. This is typically achieved through either direct administrative access to the OS shell or the successful exploitation of a separate remote code execution vulnerability elsewhere in the Pexip Infinity stack. Once a foothold is established, the attacker identifies the vulnerable internal service and crafts a malicious payload designed to exploit the input validation weakness. Because the service processes these inputs with root privileges, the lack of robust sanitization allows for the injection of commands or data structures that divert the application's execution flow.\nSpecifically, the vulnerability exists in versions prior to 38.2, as well as 39.0, 39.1, and 40.0. When an attacker sends specifically crafted requests to the internal service, they can override standard security checks, enabling the elevation of their execution context from a standard system user to root. This process does not require network exposure in the traditional sense, as the service is internal; however, it is highly dangerous as it significantly lowers the barrier for persistent, full-system compromise. Post-exploitation, an attacker with root access can bypass all filesystem permissions, install rootkits, monitor encrypted traffic, or exfiltrate sensitive configuration data, effectively gaining complete command over the Pexip Infinity node."
}