PT-2026-36887 · Arelle · Arelle

Published

2026-05-04

·

Updated

2026-05-27

·

CVE-2026-42796

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arelle versions prior to 2.39.10
Description An unauthenticated remote code execution issue exists in the '/rest/configure' REST endpoint. The endpoint accepts a plugins query parameter and forwards it to the plugin manager without requiring authentication or authorization. This allows an attacker to provide a URL to a malicious Python file via the plugins parameter, leading the Arelle webserver to download and execute the attacker-controlled code with the privileges of the Arelle process.
Recommendations Update to version 2.39.10. As a temporary workaround, restrict access to the '/rest/configure' endpoint to minimize the risk of exploitation.

Fix

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-42796

Affected Products

Arelle