CVE-2026-42796

Source
https://cve.org/CVERecord?id=CVE-2026-42796
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42796.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42796
Published
2026-05-04T17:19:43.020Z
Modified
2026-08-12T03:51:26.871847893Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Arelle < 2.39.10 Unauthenticated RCE via /rest/configure
Details

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.

Database specific
{
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42796.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/arelle/arelle

Affected ranges

Type
GIT
Repo
https://github.com/arelle/arelle
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.39.10"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.10.8
2.11.0
2.11.1
2.11.10
2.11.11
2.11.12
2.11.2
2.11.3
2.11.4
2.11.5
2.11.6
2.11.7
2.11.8
2.11.9
2.12.0
2.12.1
2.12.2
2.13.0
2.13.1
2.13.10
2.13.2
2.13.3
2.13.4
2.13.5
2.13.6
2.13.7
2.13.8
2.13.9
2.14.0
2.14.1
2.14.2
2.15.0
2.15.1
2.15.2
2.16.0
2.16.1
2.16.2
2.16.3
2.17.0
2.17.1
2.17.2
2.17.3
2.17.4
2.17.5
2.17.6
2.17.7
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.20.0
2.20.1
2.20.2
2.20.3
2.20.4
2.21.0
2.21.1
2.21.2
2.21.3
2.22.0
2.22.1
2.22.2
2.22.3
2.23.0
2.23.1
2.23.10
2.23.11
2.23.12
2.23.13
2.23.14
2.23.15
2.23.16
2.23.2
2.23.3
2.23.4
2.23.5
2.23.6
2.23.7
2.23.8
2.23.9
2.24.0
2.24.1
2.25.0
2.25.1
2.25.2
2.25.3
2.25.4
2.25.5
2.25.6
2.25.7
2.25.8
2.25.9
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.26.5
2.26.6
2.26.7
2.27.0
2.27.1
2.27.2
2.27.3
2.27.4
2.27.5
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.29.3
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.30.0
2.30.1
2.30.10
2.30.11
2.30.12
2.30.13
2.30.14
2.30.15
2.30.16
2.30.17
2.30.18
2.30.19
2.30.2
2.30.20
2.30.21
2.30.22
2.30.23
2.30.24
2.30.25
2.30.26
2.30.27
2.30.28
2.30.29
2.30.3
2.30.30
2.30.31
2.30.32
2.30.33
2.30.4
2.30.5
2.30.6
2.30.7
2.30.8
2.30.9
2.31.0
2.31.1
2.31.2
2.31.3
2.31.4
2.31.5
2.31.6
2.32.0
2.32.1
2.32.2
2.33.0
2.33.1
2.34.0
2.35.0
2.35.1
2.35.10
2.35.11
2.35.12
2.35.13
2.35.14
2.35.15
2.35.16
2.35.17
2.35.18
2.35.2
2.35.3
2.35.4
2.35.5
2.35.6
2.35.7
2.35.8
2.35.9
2.36.0
2.36.1
2.36.10
2.36.11
2.36.12
2.36.13
2.36.14
2.36.15
2.36.16
2.36.17
2.36.18
2.36.19
2.36.2
2.36.20
2.36.21
2.36.22
2.36.23
2.36.24
2.36.25
2.36.26
2.36.27
2.36.28
2.36.29
2.36.3
2.36.30
2.36.31
2.36.32
2.36.33
2.36.34
2.36.35
2.36.36
2.36.37
2.36.38
2.36.39
2.36.4
2.36.40
2.36.5
2.36.6
2.36.7
2.36.8
2.36.9
2.37.0
2.37.1
2.37.10
2.37.11
2.37.12
2.37.13
2.37.14
2.37.15
2.37.16
2.37.17
2.37.18
2.37.19
2.37.2
2.37.20
2.37.21
2.37.22
2.37.23
2.37.24
2.37.25
2.37.26
2.37.27
2.37.28
2.37.29
2.37.3
2.37.30
2.37.31
2.37.32
2.37.33
2.37.34
2.37.35
2.37.36
2.37.37
2.37.38
2.37.39
2.37.4
2.37.40
2.37.41
2.37.42
2.37.43
2.37.44
2.37.45
2.37.46
2.37.47
2.37.48
2.37.49
2.37.5
2.37.50
2.37.51
2.37.52
2.37.53
2.37.54
2.37.55
2.37.56
2.37.57
2.37.58
2.37.59
2.37.6
2.37.60
2.37.61
2.37.62
2.37.63
2.37.64
2.37.65
2.37.66
2.37.67
2.37.68
2.37.69
2.37.7
2.37.70
2.37.71
2.37.72
2.37.73
2.37.74
2.37.75
2.37.76
2.37.77
2.37.78
2.37.8
2.37.9
2.38.0
2.38.1
2.38.10
2.38.11
2.38.12
2.38.13
2.38.14
2.38.15
2.38.16
2.38.17
2.38.18
2.38.19
2.38.2
2.38.20
2.38.21
2.38.3
2.38.4
2.38.5
2.38.6
2.38.7
2.38.8
2.38.9
2.39.0
2.39.1
2.39.2
2.39.3
2.39.4
2.39.5
2.39.6
2.39.7
2.39.8
2.39.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
edgr16.*
edgr16.2
edgr16.2.1
edgr16.4
edgr17.*
edgr17.1
edgr17.3.1
edgr18.*
edgr18.1
edgr18.2
edgr18.3
edgr19.*
edgr19.1
edgr19.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42796.json"