Skip to main content
QUIETLYTIC
Vulnerability

Arelle Code Execution (CVE-2026-42796)

CVE-2026-42796 is a CVSS 9.8 unauthenticated RCE in Arelle before 2.39.10: the REST configure endpoint loads plugins from a caller-supplied URL. VulnCheck KEV.

CVE-2026-42796
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Arelle

Arelle’s /rest/configure endpoint accepts a plugins query parameter and hands it to the plugin manager with no authentication and no authorization check. Per NVD, the parameter accepts a URL, and the Arelle webserver will retrieve and run the Python it finds there inside its own process, with that process’s privileges. NVD scores CVE-2026-42796 at CVSS 3.1 base 9.8 on AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, classified as CWE-306. The flaw is fixed in Arelle 2.39.10.

NVD records the vendor as Workiva and the product as Arelle; the referenced repository is Arelle/Arelle, and the record’s references point at pull request 2320 and the 2.39.10 release tag.

The gap between the fix and the listing is the whole story

This CVE was published on May 4, 2026. The release that fixes it is referenced in the same record. VulnCheck added it to its KEV catalog on September 18, 2026 — four and a half months later.

That interval is the interesting number, and it is not evidence of a slow vendor. The fix existed before the exploitation report. What the listing marks is the moment attention arrived at the population that had not applied it. For a library-shaped dependency this is the normal failure geometry: the maintainers ship, the projects that track releases closely update within days, and a long tail of pinned, vendored, and containerised installations keeps running the vulnerable build because nothing in their pipeline is watching the upstream tag.

The operational consequence is that “have we patched Arelle?” is usually the wrong question. The right one is “where is Arelle, and who pinned it?” — an inventory problem, not a patching one.

Why an unauthenticated plugin loader is worse than an unauthenticated endpoint

Plenty of CVE-2026-42796’s peers are missing-authentication findings that expose data or a single privileged action. This one exposes the extension mechanism, which is a different class of thing.

A plugin loader exists to execute code the operator chose. It is doing exactly what it was built to do; the defect is purely in who is allowed to choose. That means there is no malformed input to filter, no injection to escape, and no parser bug to harden — the request is well-formed and the behaviour is intentional. Input validation does not help here, and neither does a generic request-inspection rule looking for anomalous content, because nothing about the traffic is anomalous. The only controls that bite are authentication in front of the endpoint, network reachability, and the version.

It also means the process privileges are the ceiling on impact, and NVD says so plainly: the code runs with the Arelle process’s privileges. Where Arelle is run as a service account with access to document stores or reporting pipelines, that ceiling is high.

The same shape appeared in this batch’s AutoAgent sandbox control-channel flaw, also CWE-306 and also VulnCheck-listed on September 18: a facility built to run code on purpose, reachable by a party who was never supposed to have it. The two products have nothing else in common, which is rather the point — the defect is architectural, not domain-specific.

Exploitation status

VulnCheck’s KEV catalog listed CVE-2026-42796 on September 18, 2026, with exploitation marked active. That is the only source in our data making the claim.

CISA’s Known Exploited Vulnerabilities catalog does not carry this CVE as of our most recent CISA KEV ingestion on September 19, 2026, so no Binding Operational Directive 26-04 remediation obligation applies to federal agencies. VulnCheck’s catalog is deliberately broader in scope than CISA’s; a listing there reports observed exploitation without carrying the federal mandate that a CISA listing does. We rate this record medium confidence — a single credible source, uncontradicted, but without the independent second source that would earn high.

What we don’t have

  • No CISA KEV listing as reflected in our ingestion through September 19, 2026.
  • No EPSS score in our ingested data, so no exploitation-probability figure to set against the severity score.
  • No structured affected-version range. “Before 2.39.10” comes from NVD’s description prose, not from a machine-readable version range in our record, and no lower bound is given — we cannot tell you which release first introduced the behaviour.
  • CVSS is single-sourced to NVD, with no corroborating or conflicting second score.
  • No deployment or exposure telemetry. We do not scan, and we make no claim about how many Arelle instances are internet-reachable.

Frequently Asked Questions

What is CVE-2026-42796? A critical (CVSS 9.8) missing-authentication flaw, CWE-306, in Arelle before 2.39.10. The /rest/configure REST endpoint forwards a caller-supplied plugins parameter to the plugin manager without authentication, so a remote unauthenticated party can cause the server to fetch and run Python code with the Arelle process’s privileges.

Which version fixes CVE-2026-42796? Arelle 2.39.10. NVD’s references for this CVE point at pull request 2320 in the Arelle/Arelle repository and at the 2.39.10 release tag.

Is CVE-2026-42796 being actively exploited? VulnCheck’s KEV catalog reports it as exploited and listed it on September 18, 2026. That is a single source; nothing in our data corroborates or contradicts it, so we rate confidence medium rather than high.

Does BOD 26-04 apply to CVE-2026-42796? No. BOD 26-04 obligations follow a CISA KEV listing, and this CVE is not on CISA’s catalog as reflected in our data through September 19, 2026.


Data sourced from the National Vulnerability Database (NVD) and VulnCheck KEV, aggregated September 19, 2026. Upstream fix: Arelle 2.39.10. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools