CVE-2026-42796 Scanner
CVE-2026-42796 Scanner - Remote Code Execution vulnerability in Arelle
Used 2.9k times · 5.9k assets checked · url
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.
CVE-2026-42796 Scanner - Remote Code Execution vulnerability in Arelle
Used 2.9k times · 5.9k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →