{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/plone.app.portlets--6.0.0--6.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:plone:plone_app_portlets:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-57149"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plone.app.portlets (\u003e= 7.0.0, \u003c= 7.0.1)","plone.app.portlets (\u003e= 6.0.0, \u003c= 6.0.3)","plone.app.portlets (\u003e= 5.0.0, \u003c= 5.0.7)"],"_cs_severities":["critical"],"_cs_tags":["rce","injection","vulnerability","web"],"_cs_type":"advisory","_cs_vendors":["Plone"],"content_html":"\u003cp\u003eThe Classic portlet component (plone.app.portlets) within Plone is vulnerable to Remote Code Execution (RCE) via a TALES (Template Attribute Language Expression Syntax) injection flaw, tracked as CVE-2026-57149. The vulnerability exists because the component improperly treats user-supplied template or macro fields as part of a TALES path expression, which is then processed by the TAL path() helper.\u003c/p\u003e\n\u003cp\u003eAn authenticated user with permissions to configure a Classic portlet can supply a crafted input that escapes basic path structures to execute arbitrary code within the server-side process. By default, regular users often possess the ability to add or edit portlets on their personal dashboards, significantly expanding the attack surface for internal privilege escalation. This vulnerability affects Plone 6.0, 6.1, and 6.2 versions via specific versions of the plone.app.portlets package.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to achieve full code execution on the server hosting the Plone instance. This results in complete system compromise, unauthorized data access, and privilege escalation from a standard user to the security context of the Plone process, impacting the confidentiality, integrity, and availability of the affected Plone installation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the affected package to the patched versions immediately:\u003c/li\u003e\n\u003cli\u003eFor Plone 6.2: Upgrade to \u003ccode\u003eplone.app.portlets\u003c/code\u003e 7.0.2.\u003c/li\u003e\n\u003cli\u003eFor Plone 6.1: Upgrade to \u003ccode\u003eplone.app.portlets\u003c/code\u003e 6.0.4.\u003c/li\u003e\n\u003cli\u003eFor Plone 6.0: Upgrade to \u003ccode\u003eplone.app.portlets\u003c/code\u003e 5.0.8.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, restrict the \u003ccode\u003eplone.app.portlets.ManageOwnPortlets\u003c/code\u003e permission from untrusted roles to prevent exploitation attempts by standard users.\u003c/li\u003e\n\u003cli\u003eAudit administrative logs for unauthorized modifications to Classic portlets as a hunt for potential exploitation attempts targeting CVE-2026-57149.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T19:56:52Z","date_published":"2026-09-23T19:56:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-plone-tales-rce/","summary":"Authenticated users can execute arbitrary code in the context of the Plone process by injecting malicious TALES expressions into Classic portlet configurations, exploitable via CVE-2026-57149.","title":"Remote Code Execution via TALES Injection in plone.app.portlets","url":"https://feed.craftedsignal.io/briefs/2026-09-plone-tales-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Plone.app.portlets (\u003e= 6.0.0, \u003c= 6.0.3)","version":"https://jsonfeed.org/version/1.1"}