Summary
CVE-2026-54569 is a critical, unauthenticated remote code execution vulnerability in SENAITE.CORE, the open-source laboratory information management system (LIMS). It results from a combination of an eval injection flaw and a missing authorization check in the JSON API, allowing unauthenticated attackers to execute arbitrary Python code on the server. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause 1 (CWE-95, Eval Injection): The JSON API’s field processing logic (invoked via the
/@@API/updateroute) calls Python’seval()on raw, user-supplied string values when parsingRecordFieldandRecordsFielddata types, before any input validation occurs. - Root cause 2 (CWE-862, Missing Authorization): The
updateroute (and related routes such asupdate_many,remove,doActionFor, anddoActionFor_many) does not enforce theAccess JSON APIpermission check that is present on other routes such ascreate, allowing anonymous/unauthenticated requests to reach the vulnerable code path. - Attack vector: Network-based; a remote, unauthenticated attacker sends a crafted JSON API request to the
/@@API/updateendpoint containing Python expressions in place of expected field values. - Impact: Arbitrary Python code execution in the application context, leading to full compromise of the underlying ZODB data store, filesystem access, and the ability to create persistent administrative accounts — resulting in complete loss of confidentiality, integrity, and availability.
Affected software
- senaite.core versions 2.0.0 through 2.6.0 (inclusive)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade senaite.core to version 2.7.0 or later, where the eval injection and missing authorization check have been fixed.
- If immediate upgrade is not possible: Apply the vendor-provided hotfix package (
SenaiteHotfix20260602) via buildout configuration and restart the instance. - Additional network mitigation: Restrict or block external access to the
/@@API/updateendpoint (and other unauthenticated JSON API state-changing routes) at a reverse proxy or WAF until the upgrade/hotfix is applied. Monitor JSON API request logs for Python syntax or suspicious eval-style payloads in request bodies.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw HTTP response body:
senaite.core.static/

