PT-2026-44075 · Pi.Alert · Pi.Alert

·

CVE-2026-44887

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pi.Alert versions prior to 2026-05-07
Description The web-based configuration editor allows the injection of arbitrary Python code into the pialert.conf file. Because the background scan daemon utilizes the exec() function to load this file, the injected code is executed with the privileges of the daemon process. When web protection is disabled, which is the default setting, this allows for unauthenticated Remote Code Execution (RCE), a process where an attacker can execute commands on a remote machine over a network.
Recommendations Update to the version released on 2026-05-07.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44887
GHSA-R59G-5WF9-F7VV

Affected Products

Pi.Alert