PT-2026-44075 · Pi.Alert · Pi.Alert
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pi.Alert versions prior to 2026-05-07
Description
The web-based configuration editor allows the injection of arbitrary Python code into the
pialert.conf file. Because the background scan daemon utilizes the exec() function to load this file, the injected code is executed with the privileges of the daemon process. When web protection is disabled, which is the default setting, this allows for unauthenticated Remote Code Execution (RCE), a process where an attacker can execute commands on a remote machine over a network.Recommendations
Update to the version released on 2026-05-07.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pi.Alert