Threat Advisory

Plone App Vulnerabilities Facilitate Manipulated Queries Within Classic Portlet

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in plone.app.dexterity and plone.app.portlets, packages for Plone, affecting stability and potentially allowing unauthorized access to system resources. The overall risk/impact is significant due to the potential for remote code execution and denial of service. Affected version ranges are not explicitly stated.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in plone.app.dexterity and plone.app.portlets, packages for Plone, affecting stability and potentially allowing unauthorized access to system resources. The overall risk/impact is significant due to the potential for remote code execution and denial of service. Affected version ranges are not explicitly stated.[emaillocker id="1283"]

CVE-2026-57149 (CVSS 9.9 — Critical): plone.app.portlets allows authenticated users who can configure Classic portlets to execute arbitrary code through crafted TALES expressions.

CVE-2026-57576 (CVSS 6.5 — Medium): plone.app.dexterity has a denial of service due to excessive title or description length potentially causing the application UI to become unresponsive.

 

RECOMMENDATIONS:

  • We recommend you to update plone.app.portlets to version 7.0.2, 6.0.4, 5.0.8 or later.
  • We recommend you to update plone.app.dexterity to version 5.0.2, 4.1.3, 3.2.3 or later.

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-rr49-f9g6-c9r5
https://github.com/advisories/GHSA-5426-92w4-wvhv

 

[/emaillocker]
crossmenu