THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jrw6-7x4q-w25j (critical) — senaite.core Vulnerable to Eval Injection and Missing Authorization

[GHSA] GHSA-jrw6-7x4q-w25j (critical) — senaite.core Vulnerable to Eval Injection and Missing Authorization

highgithub_advisoriesPublished 2026-08-26

GHSA-jrw6-7x4q-w25j Severity: critical CVE: CVE-2026-54569

senaite.core Vulnerable to Eval Injection and Missing Authorization

### Summary

An unauthenticated remote code execution vulnerability in the SENAITE JSON API allows any network-reachable attacker to execute arbitrary Python on the Zope worker process via a two-request anonymous chain. The `/@@API/update` route is reachable to anonymous

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jrw6-7x4q-w25j