CVE-2026-40177
Impact
If the 2FA was activated, it was possible to bypass the password authentication
Patches
This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ajenti/ajenti/security/advisories/GHSA-3mcx-6wxm-qr8v, https://nvd.nist.gov/vuln/detail/CVE-2026-40177, https://github.com/ajenti/ajenti, https://pypi.org/project/ajenti-plugin-core, https://github.com/advisories/GHSA-3mcx-6wxm-qr8v