CVE-2026-42796

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:*

History

27 May 2026, 18:54

Type Values Removed Values Added
First Time Workiva arelle
Workiva
CPE cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:*
References () https://github.com/Arelle/Arelle/pull/2320 - () https://github.com/Arelle/Arelle/pull/2320 - Issue Tracking, Patch
References () https://github.com/Arelle/Arelle/releases/tag/2.39.10 - () https://github.com/Arelle/Arelle/releases/tag/2.39.10 - Release Notes
References () https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure - () https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure - Third Party Advisory

04 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-04 18:16

Updated : 2026-05-27 18:54


NVD link : CVE-2026-42796

Mitre link : CVE-2026-42796

CVE.ORG link : CVE-2026-42796


JSON object : View

Products Affected

workiva

  • arelle
CWE
CWE-306

Missing Authentication for Critical Function