Pi.Alert · Pi.Alert · CVE-2026-44887
**Name of the Vulnerable Software and Affected Versions**
Pi.Alert versions prior to 2026-05-07
**Description**
The web-based configuration editor allows the injection of arbitrary Python code into the `pialert.conf` file. Because the background scan daemon utilizes the `exec()` function to load this file, the injected code is executed with the privileges of the daemon process. When web protection is disabled, which is the default setting, this allows for unauthenticated Remote Code Execution (RCE), a process where an attacker can execute commands on a remote machine over a network.
**Recommendations**
Update to the version released on 2026-05-07.