PT-2026-44076 · Pi.Alert · Pi.Alert

·

CVE-2026-44888

·

Published

2026-05-27

·

Updated

2026-05-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pi.Alert versions prior to 2026-05-07
Description The SaveConfigFile() endpoint writes user-supplied numeric configuration values, such as SMTP PORT, directly into the pialert.conf file without validation. Because the background cron process loads pialert.conf using the Python exec() function every 3 to 5 minutes, an attacker can inject arbitrary Python code to achieve unauthenticated operating system-level remote code execution (RCE). On default installations where PIALERT WEB PROTECTION is set to False, no credentials are required to exploit this issue.
Recommendations Update to the version released on 2026-05-07.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44888
GHSA-XG85-F8QW-7C5F

Affected Products

Pi.Alert