Arbitrary Code Execution Vulnerability in Plone Classic Portlet by Plone
CVE-2026-57149
What is CVE-2026-57149?
The Classic portlet in plone.app.portlets prior to versions 5.0.8, 6.0.4, and 7.0.2 contains a vulnerability that allows authenticated users to input malicious template values. This can lead to the execution of arbitrary code within the Plone process, facilitating privilege escalation between authenticated users and the server-side environment. To mitigate this risk, it is advised to remove the 'plone.app.portlets.ManageOwnPortlets' permission for untrusted roles and limit portlet management to authorized administrators. Additionally, unregistering or customizing the Classic portlet can further reduce exposure.
Affected Version(s)
plone.app.portlets >= 7.0.0, < 7.0.2 < 7.0.0, 7.0.2
plone.app.portlets >= 6.0.0, < 6.0.4 < 6.0.0, 6.0.4
plone.app.portlets >= 5.0.0, < 5.0.8 < 5.0.0, 5.0.8
