External risk intelligence

Pexip Infinity Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-103110

Pexip Infinity Conferencing Nodes are designed as public-facing gateways and infrastructure for video conferencing, requiring direct internet connectivity for external participants and remote communication in standard deployments.

Out-of-bounds Write

Pexip Infinity

before 38.239.0 to 39.140.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in Pexip Infinity, a video conferencing platform. This issue involves improper input validation, which could allow an unauthorized remote attacker to execute code on a Pexip Infinity Conferencing Node. This could potentially impact the integrity and availability of video conferencing services.

  • Vulnerability allows remote code execution.
  • Confirms exposure of public-facing gateways.
  • Assess impact on conferencing services.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input over the network to a Pexip Infinity Conferencing Node. This input would trigger improper input validation within the system, allowing the attacker to execute arbitrary code as an unprivileged user, potentially leading to a full compromise of the node.

  • No authentication or user interaction needed.
  • Unprivileged remote code execution.
  • Complete system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute code as an unprivileged user on a Pexip Infinity Conferencing Node. This could potentially affect the confidentiality, integrity, and availability of the conferencing node and its services when supported by the advisory.

  • System data and service behavior at risk.
  • Remote code execution via improper input validation.
  • Disruption of conferencing services.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Pexip Infinity platform, particularly its Conferencing Nodes, is likely managed by a combination of infrastructure, platform, and security teams due to its role as a public-facing gateway. The immediate priority is to identify all Pexip Infinity instances, determine their exposure and criticality, and then coordinate with the accountable owner for remediation planning, potentially involving vendor engagement.

  • Identify Pexip Infinity instances and their exposure.
  • Confirm business criticality and accountable system owners.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Pexip Infinity?

Pexip Infinity is a software platform used to host and manage enterprise video conferencing services. It utilizes Conferencing Nodes to act as gateways, facilitating communication between different video systems and allowing participants to join meetings across various networks.

How does CVE-2026-103110 trigger code execution?

This vulnerability is classified as improper input validation, specifically identified as CWE-787. It occurs when the software incorrectly processes data sent by a remote user. An attacker can leverage this flaw by sending specially crafted network traffic to a Conferencing Node, which forces the system to execute unauthorized code.

Do I need to authenticate to trigger this bug?

No. The vulnerability does not require the attacker to have legitimate access or credentials. It also does not rely on any user interaction, such as clicking a link or opening a file. Simply sending the malicious input to a reachable Conferencing Node is sufficient to attempt exploitation.

Why is this a high-priority risk for my infrastructure?

Halo Surface Signal indicates that Pexip Infinity Conferencing Nodes are typically designed as public-facing gateways. Because these nodes often require direct internet connectivity to function correctly for remote participants, they are naturally exposed to external network threats that can reach this vulnerability.

How should I respond to CVE-2026-103110?

Your first step is to create an inventory of all Pexip Infinity Conferencing Nodes in your environment. Once identified, consult official Pexip security documentation to confirm if your specific version is affected and apply the recommended software updates provided by the vendor to resolve the input validation weakness.

References