天下漏洞,尽知其名
HIGH

CVE-2026-103106 Pexip Infinity 输入验证不当提权漏洞

影响本地攻击者可将权限提升至 root

AI 研判

Pexip Infinity 内部服务存在输入验证不当问题,攻击者可利用该缺陷提升权限。该漏洞影响 38.2 之前版本以及 39.0、39.1、40.0 版本。

影响范围

Pexip Infinity

Pexip Infinity 38.2 之前版本,以及 39.0、39.1、40.0 版本。

漏洞详情

漏洞源于 Pexip Infinity 内部服务未对输入进行充分校验,属于输入验证不当类缺陷。攻击者需先在节点上执行任意代码(通过其他漏洞实现远程代码执行或拥有操作系统管理权限),随后利用该缺陷将权限提升至 root。

利用条件与风险

利用前提是攻击者已能在目标节点执行任意代码或拥有操作系统管理权限,属于本地提权,单独利用难度较高,但与其他漏洞组合可造成严重危害。

修复建议

建议升级至 Pexip Infinity 38.2 或更高版本(39.0、39.1、40.0 用户应关注官方修复版本)。临时缓解措施暂无公开信息。

原始情报

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.