← Back

Workiva

workiva

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Arelle
arelle

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Workiva
1Arelle
Jun 17, 2026
May 4, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authenticati...Show more
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.Show less