Known CVE
Arelle < 2.39.10 - Remote Code Execution
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the webserver's /rest/configure endpoint. The plugins query parameter is forwarded to the plugin manager without authentication, allowing an attacker to supply a URL to a remote Python file that Arelle downloads and executes within its process.
CVE-2026-42796
Critical2026CVSS 9.8CWE-306
cve2026 · arelle · rce · oast · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website