CVE-2026-35175
Impact
An authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser.
Patches
This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ajenti/ajenti/security/advisories/GHSA-73jv-44c3-j5p2, https://nvd.nist.gov/vuln/detail/CVE-2026-35175, https://github.com/ajenti/ajenti, https://github.com/ajenti/ajenti/releases/tag/v2.2.15
