Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.
References
| Link | Resource |
|---|---|
| https://github.com/Arelle/Arelle/pull/2320 | Issue Tracking Patch |
| https://github.com/Arelle/Arelle/releases/tag/2.39.10 | Release Notes |
| https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure | Third Party Advisory |
Configurations
History
27 May 2026, 18:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Workiva arelle
Workiva |
|
| CPE | cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Arelle/Arelle/pull/2320 - Issue Tracking, Patch | |
| References | () https://github.com/Arelle/Arelle/releases/tag/2.39.10 - Release Notes | |
| References | () https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure - Third Party Advisory |
04 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-04 18:16
Updated : 2026-05-27 18:54
NVD link : CVE-2026-42796
Mitre link : CVE-2026-42796
CVE.ORG link : CVE-2026-42796
JSON object : View
Products Affected
workiva
- arelle
CWE
CWE-306
Missing Authentication for Critical Function
