CVE-2026-42796
CRITICALArelle < 2.39.10 Unauthenticated RCE via /rest/configure
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-42796. PoCs published by ameerhamza-malik.
AI-analyzed exploit summary The repository contains a minimal Python script that prints a success message but lacks any functional exploit code or technical details related to CVE-2026-42796. It appears to be a placeholder or stub.
Description
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.
Exploits (1)
The repository contains a minimal Python script that prints a success message but lacks any functional exploit code or technical details related to CVE-2026-42796. It appears to be a placeholder or stub.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H