VDB
Sign up
—

PYSEC-2026-2339

Ajenti has an authorization bypass during custom package installation

Quick fix

PYSEC-2026-2339 — ajenti-panel: upgrade to the fixed version with the command below.

pip install --upgrade 'ajenti-panel>=2.2.15'

Details

### Impact

An authenticated user (using the `auth_users` plugin authentication method) could install a custom package even if this user is not superuser.

### Patches

This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ajenti-panel
Introduced in: 0Fixed in: 2.2.15
Fixpip install --upgrade 'ajenti-panel>=2.2.15'

References