#VU125026 Improper access control in lupa - CVE-2026-34444

 

#VU125026 Improper access control in lupa - CVE-2026-34444

Published: April 7, 2026


Vulnerability identifier: #VU125026
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2026-34444
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
lupa
Software vendor:
scoder (scoder)

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to incomplete attribute_filter enforcement in getattr / setattr. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links