ajenti.plugin.core has password bypass when 2FA is activated
Description
Published to the GitHub Advisory Database
Apr 10, 2026
Reviewed
Apr 10, 2026
Published by the National Vulnerability Database
Apr 10, 2026
Last updated
Apr 24, 2026
Impact
If the 2FA was activated, it was possible to bypass the password authentication
Patches
This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.
References