CVE-2026-42796

CRITICAL

Arelle < 2.39.10 Unauthenticated RCE via /rest/configure

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-42796. PoCs published by ameerhamza-malik.

AI-analyzed exploit summary The repository contains a minimal Python script that prints a success message but lacks any functional exploit code or technical details related to CVE-2026-42796. It appears to be a placeholder or stub.

Description

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.

Exploits (1)

nomisec STUB
by ameerhamza-malik · poc
https://github.com/ameerhamza-malik/CVE-2026-42796

The repository contains a minimal Python script that prints a success message but lacks any functional exploit code or technical details related to CVE-2026-42796. It appears to be a placeholder or stub.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
Prerequisites: none
devstral-2 · analyzed May 08, 2026 Full analysis →

References (3)

Core 3
Core References
Issue Tracking issue-tracking
https://github.com/Arelle/Arelle/pull/2320

Scores

CVSS v3 9.8
EPSS 0.0053
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
Arelle/Arelle < 2.39.10
workiva/arelle < 2.39.10
Published May 04, 2026
Tracked Since May 04, 2026