CVE-2026-42796Disclosure(workiva / arelle)

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch workiva arelle systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arelle

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-04); latest day: 1
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
arelle

Deep dive

Activity timeline10 mentions / 4d
01234Mentions · 2026-05-04: 4Mentions · 2026-05-13: 4Mentions · 2026-05-16: 1Mentions · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-23: 1Patch / Workaround · 2026-05-04: 2Technical Details · 2026-05-04: 4Technical Details · 2026-05-13: 3Technical Details · 2026-07-23: 105-0405-1305-1607-23
Signal classification3 categories
Disclosure
550.0%
General
330.0%
Patch
220.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-044
Disclosure2Patch2
2026-05-134
Disclosure2General2
2026-05-161
General1
2026-07-231
Disclosure1
Full discourse10 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-42796 - critical 🚨 Arelle < 2.39.10 - Remote Code Execution > Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-42796 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE‑2026‑42796 as a critical unauthenticated RCE affecting Arelle versions older than 2.39.10 and provides a link to a Project Discovery library page for further details.

    01002316
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42796 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a…

    Post summary

    The advisory announces a critical unauthenticated remote code execution vulnerability in Arelle before version 2.39.10, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42796 (CVSS 9.8) — multiple products. CVE: CVE-2026-42796 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    Advisory announces CVE-2026-42796 as a critical vulnerability with CVSS 9.8; no PoC, exploit, patch, or active exploitation details are provided.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42796 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry lists a critical CVE (CVE-2026-42796) with its CVSS score and severity, but no further technical or operational details are provided.

    1000040
    210 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Arelle Unauthenticated RCE (CVE-2026-42796) arelle REST API allows loading external plugins via /rest/configure without authentication, leading to remote code execution. 👉 Update to 2.39.10 immediately

    Post summary

    Arelle’s REST API allows unauthenticated loading of external plugins, providing a remote code execution vector. Users are urged to update immediately to version 2.39.10.

    0001073
    122 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-42796 — CVSS 9.8/10 ██████████ Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/1kAGb0rclX

    Post summary

    The message announces the critical CVE‑2026‑42796 remote code execution flaw in Arelle < 2.39.10 and that a patch is now available; no PoC, exploit details, or active exploitation reports are provided.

    1000054
    26 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42796: Arelle Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04gTCWZ0

    Post summary

    The text is a brief headline that announces the CVE and alludes to its business implications, but offers no concrete details on exploitation, mitigation, or technical specifics.

    0000038
    31 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42796-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided snippet only references a URL and generic hashtags, offering no specific information on the CVE, so it is classified as General with low confidence.

    0000025
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42796 Unauthenticated Remote Code Execution in Arelle Before 2.39.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42796

    Post summary

    The post announces a new RCE vulnerability (CVE-2026-42796) in Arelle before version 2.39.10, without providing PoCs, exploits, or patch information.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42796 Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and … https://www.cve.org/CVERecord?id=CVE-2026-42796

    Post summary

    CVE‑2026‑42796 describes an unauthenticated RCE in Arelle’s REST API; no PoC, exploit, active use, or patch information is provided.

    00000115
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appworkivaarelle---

Explore more