CVE-2026-40177 - Password bypass when 2FA is activated
CVE ID :CVE-2026-40177
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Pr...
Related Vulnerabilities
- CVE-2026-33707: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password r CRITICAL
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
- CVE-2026-35647: OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass MEDIUM
Related Coverage
Threat Actors