Sceawere

Vulnerability Detail

CVE-2026-103106UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Local Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-669 Incorrect Resource Transfer Between Spheres
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-30T03:16:59.773Z",
  "pubdate": "2026-09-30T03:16:59.773Z",
  "executiveSummary": "Pexip Infinity is susceptible to a local privilege escalation vulnerability caused by improper input validation within an internal service. This flaw enables an attacker who has already established a foothold on a node to escalate their privileges to root. The vulnerability affects Pexip Infinity versions prior to 38.2, as well as versions 39.0, 39.1, and 40.0. The risk is significant as it facilitates complete system compromise following the initial breach. Exploitation requires the attacker to have pre-existing local access to the operating system or the ability to execute arbitrary code via a separate, secondary exploit. By interacting with the vulnerable internal service, a low-privileged user can manipulate input vectors to gain unauthorized administrative control over the underlying host. Organizations should prioritize patching to remediate the vulnerable component and limit potential lateral movement or system-level compromise.",
  "technicalDetails": "The vulnerability originates from improper input validation logic residing within an internal service component of Pexip Infinity. This service, which operates with elevated privileges, fails to adequately sanitize or constrain inputs provided by local processes. The architectural flaw allows a process executing with limited user-level permissions to interact with the service in a manner that triggers an unintended execution path or memory manipulation, resulting in privilege escalation.\nThe attack flow requires an adversary to first establish execution capability on the target node. This is typically achieved through either direct administrative access to the OS shell or the successful exploitation of a separate remote code execution vulnerability elsewhere in the Pexip Infinity stack. Once a foothold is established, the attacker identifies the vulnerable internal service and crafts a malicious payload designed to exploit the input validation weakness. Because the service processes these inputs with root privileges, the lack of robust sanitization allows for the injection of commands or data structures that divert the application's execution flow.\nSpecifically, the vulnerability exists in versions prior to 38.2, as well as 39.0, 39.1, and 40.0. When an attacker sends specifically crafted requests to the internal service, they can override standard security checks, enabling the elevation of their execution context from a standard system user to root. This process does not require network exposure in the traditional sense, as the service is internal; however, it is highly dangerous as it significantly lowers the barrier for persistent, full-system compromise. Post-exploitation, an attacker with root access can bypass all filesystem permissions, install rootkits, monitor encrypted traffic, or exfiltrate sensitive configuration data, effectively gaining complete command over the Pexip Infinity node."
}
CVE-2026-103106: Pexip Infinity Local Privilege Escalation (HIGH Severity, CVSS: 7.8) | Sceawere