{"id":"CVE-2026-103110","published":"2026-09-30T04:18:29.077","lastModified":"2026-09-30T04:18:29.077","description":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://docs.pexip.com/admin/security_bulletins.htm","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows a remote attacker to execute code on a Pexip Infinity Conferencing Node, leading to potential unauthorized access and control of the system.","exploitability":"Exploitation is relatively straightforward as it requires only remote access and can be performed by an unprivileged user.","blast_radius":"If exploited, the impact could be severe, potentially leading to complete system compromise and unauthorized execution of arbitrary code.","remediation":"Upgrade to Pexip Infinity version 38.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-execution","remote","unprivileged"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:48:54.309Z"}}