Skip to content
Security Alerts

CVE-2026-42796: Unauthenticated RCE in Arelle (/rest/configure)

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure endpoint - the plugins parameter is forwarded to the plugin manager without authorization, allowing remote code execution...

Summary

ParameterValue
CVE IDCVE-2026-42796
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-05-04
VendorArelle
ProductArelle
CVSS Score9.8 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.

Required Actions

Update Arelle to version 2.39.10 or later immediately. Until the patch is deployed, block access to the /rest/configure endpoint at the reverse proxy or web application firewall, and run the Arelle server only in an isolated network segment. Review server logs for requests to /rest/configure carrying unusual plugins parameter values.

Who Is Affected?

This vulnerability affects Arelle in versions prior to 2.39.10. Check whether your organization uses Arelle to process XBRL reports and update the installation without delay.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist