Arbitrary Code Execution Vulnerability in Plone Classic Portlet by Plone
CVE-2026-57149

9.9CRITICAL

Key Information:

Vendor

Plone

Vendor
CVE Published:
22 September 2026

What is CVE-2026-57149?

The Classic portlet in plone.app.portlets prior to versions 5.0.8, 6.0.4, and 7.0.2 contains a vulnerability that allows authenticated users to input malicious template values. This can lead to the execution of arbitrary code within the Plone process, facilitating privilege escalation between authenticated users and the server-side environment. To mitigate this risk, it is advised to remove the 'plone.app.portlets.ManageOwnPortlets' permission for untrusted roles and limit portlet management to authorized administrators. Additionally, unregistering or customizing the Classic portlet can further reduce exposure.

Affected Version(s)

plone.app.portlets >= 7.0.0, < 7.0.2 < 7.0.0, 7.0.2

plone.app.portlets >= 6.0.0, < 6.0.4 < 6.0.0, 6.0.4

plone.app.portlets >= 5.0.0, < 5.0.8 < 5.0.0, 5.0.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.