PT-2026-59010 · Pypi · Accesscontrol

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Impact

Anonymous users can delete the user data maintained by an AccessControl.userfolder.UserFolder which may prevent any privileged access.

Patches

The problem is fixed in version 7.2.

Workarounds

The problem can be fixed by adding data roles = () to AccessControl.userfolder.UserFolder.

References

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2326

Affected Products

Accesscontrol