Sceawere

Vulnerability Detail

CVE-2026-103110UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Remote Code Execution

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-30T04:18:29.077Z",
  "pubdate": "2026-09-30T04:18:29.077Z",
  "executiveSummary": "Pexip Infinity versions prior to 38.2, 39.0, 39.1, and 40.0 are vulnerable to a remote code execution (RCE) flaw stemming from improper input validation. The vulnerability resides within the Conferencing Node component, allowing an unauthenticated remote attacker to execute arbitrary commands. By leveraging this input validation failure, an adversary can achieve code execution under the context of an unprivileged user on the affected node. This represents a critical security risk as it facilitates potential system compromise, lateral movement within the network, or unauthorized access to sensitive conferencing data. The exploitation does not explicitly require prior authentication, making the attack surface significant for internet-exposed Pexip Infinity deployments. Remediation requires updating the affected Conferencing Nodes to a patched version to rectify the validation logic errors.",
  "technicalDetails": "The vulnerability is identified as an improper input validation flaw within the Pexip Infinity Conferencing Node software. Input validation vulnerabilities occur when an application processes user-supplied data without adequate sanitization or boundary checking, allowing malicious payloads to alter intended program execution flow. In this specific instance, the lack of sufficient input verification on the Conferencing Node allows an attacker to inject and execute arbitrary code.\nThe attack flow begins with a remote attacker identifying an internet-facing Pexip Infinity Conferencing Node. By sending specially crafted network requests that contain malicious input, the attacker exploits the flawed validation mechanism. Because the input processing routines do not strictly enforce schema or content constraints, the underlying application can be coerced into interpreting these inputs as executable commands or system instructions.\nUpon successful exploitation, the malicious payload is executed by the system in the context of an unprivileged user. While the process runs with limited permissions, the impact remains severe. The attacker can use this initial foothold to probe the internal network, intercept conferencing metadata, or attempt privilege escalation attacks to obtain higher-level administrative access to the Conferencing Node. The inability of the Conferencing Node to distinguish between valid operational input and malicious command injection effectively bypasses standard security boundaries.\nAffected versions include all iterations prior to 38.2, as well as standalone versions 39.0, 39.1, and 40.0. The vulnerability is characterized by its remote exploitability, meaning an attacker does not require physical or local access to the appliance. The network exposure is high for deployments where the Conferencing Node is reachable from untrusted network segments. Post-exploitation behavior typically involves the establishment of a command-and-control channel or the exfiltration of system information, further compromising the integrity and confidentiality of the Pexip Infinity environment.\nDefensive analysis indicates that the root cause lies in the handling of external requests that reach the Conferencing Node's processing engine. To prevent exploitation, the application's input processing logic must be reinforced to implement strict allow-listing of incoming data formats and ensure that all user-provided input is sanitized before it reaches critical system components."
}
CVE-2026-103110: Pexip Infinity Remote Code Execution (CRITICAL Severity, CVSS: 9.8) | Sceawere