{"id":"PYSEC-2026-2076","summary":"Access control vulnerable to user data deletion by anonynmous users","details":"### Impact\nAnonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access.\n\n### Patches\nThe problem is fixed in version 7.2.\n\n### Workarounds\nThe problem can be fixed by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.\n\n### References\nhttps://github.com/zopefoundation/AccessControl/issues/159","aliases":["CVE-2024-51734","GHSA-g5vw-3h65-2q3v","PYSEC-2026-2326"],"modified":"2026-07-13T16:43:09.124567216Z","published":"2026-07-07T14:34:43.747557Z","references":[{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-g5vw-3h65-2q3v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51734"},{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/issues/159"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/AccessControl"},{"type":"PACKAGE","url":"https://pypi.org/project/zope"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g5vw-3h65-2q3v"}],"affected":[{"package":{"name":"zope","ecosystem":"PyPI","purl":"pkg:pypi/zope"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.11.1"}]}],"versions":["4.0","4.0b1","4.0b10","4.0b2","4.0b3","4.0b4","4.0b5","4.0b6","4.0b7","4.0b8","4.0b9","4.1","4.1.1","4.1.2","4.1.3","4.2","4.2.1","4.3","4.4","4.4.1","4.4.2","4.4.3","4.4.4","4.5","4.5.1","4.5.2","4.5.3","4.5.4","4.5.5","4.6","4.6.1","4.6.2","4.6.3","4.7","4.8","4.8.1","4.8.10","4.8.11","4.8.2","4.8.3","4.8.4","4.8.5","4.8.6","4.8.7","4.8.8","4.8.9","5.0","5.0a1","5.0a2","5.1","5.1.1","5.1.2","5.10","5.11","5.2","5.2.1","5.3","5.4","5.5","5.5.1","5.5.2","5.6","5.7","5.7.1","5.7.2","5.7.3","5.8","5.8.1","5.8.2","5.8.3","5.8.4","5.8.5","5.8.6","5.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/zope/PYSEC-2026-2076.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}]}