{"id":"CVE-2026-42796","summary":"Arelle \u003c 2.39.10 Unauthenticated RCE via /rest/configure","details":"Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.","modified":"2026-08-12T03:51:26.871847893Z","published":"2026-05-04T17:19:43.020Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42796.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-306"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42796.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42796"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/arelle-unauthenticated-rce-via-rest-configure"},{"type":"REPORT","url":"https://github.com/Arelle/Arelle/pull/2320"},{"type":"FIX","url":"https://github.com/Arelle/Arelle/releases/tag/2.39.10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/arelle/arelle","events":[{"introduced":"0"},{"fixed":"0733db1f789202e3417d2b71dbd02d486da01299"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.39.10"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:workiva:arelle:*:*:*:*:*:*:*:*"}}],"versions":["2.39.7","2.39.9","2.39.8","2.39.6","2.39.5","2.39.4","2.39.3","2.39.2","2.39.1","2.39.0","2.38.21","2.38.20","2.38.19","2.38.18","2.38.17","2.38.16","2.38.15","2.38.14","2.38.13","2.38.12","2.38.11","2.38.10","2.38.9","2.38.8","2.38.7","2.38.6","2.38.5","2.38.4","2.38.3","2.38.2","2.38.1","2.38.0","2.37.78","2.37.77","2.37.76","2.37.75","2.37.74","2.37.73","2.37.72","2.37.71","2.37.70","2.37.69","2.37.68","2.37.67","2.37.66","2.37.65","2.37.64","2.37.63","2.37.62","2.37.61","2.37.60","2.37.59","2.37.58","2.37.57","2.37.56","2.37.55","2.37.54","2.37.53","2.37.52","2.37.51","2.37.50","2.37.49","2.37.48","2.37.47","2.37.46","2.37.45","2.37.44","2.37.43","2.37.42","2.37.41","2.37.40","2.37.39","2.37.38","2.37.36","2.37.37","2.37.35","2.37.34","2.37.33","2.37.32","2.37.31","2.37.30","2.37.29","2.37.28","2.37.27","2.37.26","2.37.25","2.37.24","2.37.23","2.37.22","2.37.21","2.37.20","2.37.19","2.37.18","2.37.17","2.37.16","2.37.15","2.37.14","2.37.13","2.37.11","2.37.12","2.37.10","2.37.9","2.37.8","2.37.7","2.37.6","2.37.5","2.37.4","2.37.3","2.37.2","2.37.1","2.37.0","2.36.40","2.36.39","2.36.38","2.36.37","2.36.36","2.36.35","2.36.34","2.36.33","2.36.32","2.36.31","2.36.30","2.36.29","2.36.28","2.36.27","2.36.26","2.36.25","2.36.24","2.36.23","2.36.22","2.36.21","2.36.20","2.36.19","2.36.18","2.36.17","2.36.16","2.36.15","2.36.14","2.36.13","2.36.12","2.36.11","2.36.10","2.36.9","2.36.8","2.36.7","2.36.6","2.36.5","2.36.4","2.36.3","2.36.2","2.36.1","2.36.0","2.35.18","2.35.17","2.35.16","2.35.15","2.35.14","2.35.13","2.35.12","2.35.8","2.35.11","2.35.10","2.35.9","2.35.7","2.35.6","2.35.5","2.35.4","2.35.3","2.35.2","2.35.1","2.35.0","2.34.0","2.33.1","2.33.0","2.32.2","2.32.1","2.32.0","2.31.6","2.31.5","2.31.4","2.31.3","2.31.2","2.31.1","2.31.0","2.30.33","2.30.32","2.30.31","2.30.30","2.30.29","2.30.28","2.30.27","2.30.19","2.30.26","2.30.25","2.30.24","2.30.22","2.30.23","2.30.21","2.30.20","2.30.18","2.30.17","2.30.16","2.30.15","2.30.14","2.30.13","2.30.12","2.30.10","2.30.11","2.30.9","2.30.7","2.30.8","2.30.5","2.30.6","2.30.4","2.30.3","2.30.2","2.30.1","2.30.0","2.29.3","2.29.2","2.29.1","2.29.0","2.28.1","2.28.0","2.27.5","2.27.4","2.27.3","2.27.2","2.27.1","2.27.0","2.26.7","2.26.6","2.26.5","2.26.4","2.26.3","2.26.2","2.26.1","2.26.0","2.25.8","2.25.9","2.25.7","2.25.6","2.25.5","2.25.4","2.25.3","2.25.2","2.25.1","2.25.0","2.24.1","2.24.0","2.23.16","2.23.15","2.23.14","2.23.13","2.23.12","2.23.11","2.23.10","2.23.9","2.23.8","2.23.7","2.23.6","2.23.5","2.23.4","2.23.3","2.23.2","2.23.1","2.23.0","2.22.3","2.22.2","2.22.1","2.22.0","2.21.3","2.21.1","2.21.2","2.21.0","2.20.4","2.20.3","2.20.1","2.20.2","2.20.0","2.19.1","2.19.0","2.18.0","2.17.7","2.17.6","2.17.5","2.17.4","2.17.3","2.17.2","2.17.1","2.17.0","2.16.3","2.16.2","2.16.1","2.16.0","2.15.2","2.15.1","2.14.1","2.15.0","2.14.2","2.14.0","2.13.10","2.13.9","2.13.8","2.13.7","2.13.6","2.13.5","2.13.4","2.13.3","2.13.2","2.13.1","2.13.0","2.12.2","2.12.1","2.12.0","2.11.12","2.11.11","2.11.10","2.11.9","2.11.8","2.11.7","2.11.6","2.11.5","2.11.4","2.11.3","2.11.2","2.11.1","2.11.0","2.10.8","2.10.7","2.10.6","2.10.5","2.10.4","2.10.3","2.10.2","2.10.1","2.10.0","2.9.0","2.8.1","2.8.0","2.7.1","2.7.0","2.6.0","2.5.8","2.5.7","2.5.6","2.5.5","2.5.4","2.5.3","2.5.2","2.5.1","2.5.0","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.3.4","2.3.3","2.3.2","2.3.1","2.3.0","2.2.4","2.2.3","2.2.2","2.2.1","2.2.0","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.0","edgr19.2.1","edgr19.1","edgr18.3","edgr18.2","edgr18.1","edgr17.3.1","edgr17.1","edgr16.4","edgr16.2.1","edgr16.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42796.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}