CVE-2026-42796

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-04 18:16

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42796

Mitre link : CVE-2026-42796

CVE.ORG link : CVE-2026-42796


JSON object : View

Products Affected

workiva

  • arelle
CWE
CWE-306

Missing Authentication for Critical Function