External risk intelligence

Ajenti Plugin Installation Allows Root Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-79920

Ajenti is a server administration panel designed to be accessed over a network to manage Linux and BSD systems. As a remote management interface, it is commonly deployed as an internet-facing or edge-accessible service for administrative purposes, making the vulnerable endpoint reachable in typical deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Ajenti, a server administration panel for Linux and BSD systems. An authenticated user with low privileges can exploit this flaw to gain root code execution and full host compromise by manipulating plugin installations. The issue has been fixed in a later version.

  • Unauthenticated users can gain root access.
  • Affects systems managed by Ajenti.
  • Confirm Ajenti relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with existing access to the Ajenti server panel, even with low privileges, can exploit this vulnerability. By interacting with the panel's API, they can initiate plugin management tasks that are not properly authorized. This allows them to manipulate which plugins are installed, uninstalled, or upgraded, leading to the execution of arbitrary code with root privileges and complete control over the server.

  • Authenticated user access required.
  • Unvalidated plugin names and versions enqueued.
  • Root code execution and full host compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an authenticated user with low privileges could leverage this vulnerability to execute arbitrary code with root privileges on the affected system. This could occur when the system enqueues plugin installation or upgrade tasks, allowing the manipulation of pip package specifications.

  • Root code execution on the server.
  • Authenticated user enqueueing malicious tasks.
  • Full host compromise by an attacker.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners and platform teams are likely responsible for addressing this vulnerability in Ajenti, a server administration panel. The immediate practical step is to inventory all Ajenti instances, confirm their network exposure and business criticality, and identify the specific teams or individuals accountable for each deployment. This will enable a risk-based remediation plan, coordinating with vendor management if necessary.

  • Identify Ajenti deployments and accountable owners.
  • Verify network exposure and business criticality.
  • Plan coordinated remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Ajenti?

Ajenti is a web-based administration panel for Linux and BSD systems. It provides a graphical interface that allows system administrators to manage services, configuration files, and packages remotely, serving as a centralized dashboard for server maintenance tasks.

What is the weakness behind CVE-2026-79920?

This vulnerability is classified as CWE-862, which is a Missing Authorization flaw. In Ajenti, the software fails to verify if a user has the appropriate administrative permissions before allowing them to trigger sensitive plugin management tasks via the API, such as installing or upgrading software packages.

How can an attacker trigger this vulnerability?

An attacker must have an authenticated account on the Ajenti panel to interact with the vulnerable API endpoint. Simply being an unauthenticated visitor is not enough to trigger the bug. Once logged in as a low-privileged user, they can send commands to the system that incorrectly bypass security checks to execute code as root.

Is my server at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because Ajenti is a remote management interface designed for network access, it is often deployed in internet-facing or edge-accessible configurations. If your instance is reachable over the network, it may be accessible to attackers, increasing the relevance of this security flaw to your environment.

What should I do to address this issue?

The primary response is to update your Ajenti software to version 2.2.16 or later, which contains the fix for this authorization bypass. Before applying the update, inventory your active Ajenti deployments and coordinate with the teams responsible for these systems to ensure the patch is applied across your infrastructure.

References