CRITICAL
9.8 CVE-2026-54569 Published 26 Aug 2026
SENAITE.CORE Unauthenticated RCE in JSON API
Worried this affects one of your servers?
SENAITE.CORE, the core framework for the SENAITE laboratory information management system, is affected.
From version 2.0.0 to 2.6.0, the JSON API permits unauthenticated remote code execution through a two-request chain.
The issue lies in missing authorization checks for state-changing routes and unsafe evaluation of raw request values.
An attacker can exploit this to execute arbitrary Python code, exposing or modifying laboratory data, files, and accounts, and potentially disrupting the service.
Reference: CVE-2026-54569 on NVD
← Back to Security News