{"id":"PYSEC-2026-4022","summary":"Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions","details":"### Impact\nPython's string `format` functionality allows someone controlling the format string to \"read\" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses and subscriptions use Python's full blown `getattr` and `getitem`, not the policy restricted `AccessControl` variants `_getattr_` and `_getitem_`. This can lead to critical information disclosure.\n\nThe `AccessControl` package already guards against direct access to the formatting functions on string instances, but these mitigations did not cover subclasses of `str`.\n\nAffected are all users who allow untrusted users to create AccessControl controlled Python code and execute it.\n\n### Patches\nA fix was published with version 7.4.\n\n### Workarounds\nThere is no workaround.","aliases":["CVE-2026-77401","GHSA-pq59-9fq7-m886"],"modified":"2026-10-01T17:45:03.127620253Z","published":"2026-10-01T16:38:32.886701Z","references":[{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-pq59-9fq7-m886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77401"},{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/commit/f980450eea416718be62847f34dfd51822938e43"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/AccessControl"},{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/releases/tag/7.4"},{"type":"PACKAGE","url":"https://pypi.org/project/accesscontrol"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pq59-9fq7-m886"}],"affected":[{"package":{"name":"accesscontrol","ecosystem":"PyPI","purl":"pkg:pypi/accesscontrol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4"}]}],"versions":["2.13.0","2.13.1","2.13.10","2.13.11","2.13.12","2.13.13","2.13.14","2.13.15","2.13.16","2.13.2","2.13.3","2.13.4","2.13.5","2.13.6","2.13.7","2.13.8","2.13.9","3.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","4.0","4.0a1","4.0a2","4.0a3","4.0a4","4.0a5","4.0a6","4.0a7","4.0b1","4.0b2","4.0b3","4.0b4","4.0b5","4.0b6","4.0b7","4.1","4.2","4.3","4.4","5.0","5.1","5.2","5.3","5.3.1","5.4","5.5","5.6","5.7","6.0","6.1","6.2","6.3","7.0","7.1","7.2","7.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/accesscontrol/PYSEC-2026-4022.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"}]}