---
id: CVE-2002-0688
aliases:
  - GHSA-7944-h5rw-qmjx
  - PYSEC-2026-755
title: ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
summary: ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
severity: high
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.4.0, < 2.6.0'
patched:
  - zope 2.6.0
published: '2022-04-30'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7944-h5rw-qmjx'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2002-0688'
  - url: >-
      https://web.archive.org/web/20020810160608/http://www.zope.org/Products/Zope/Hotfix_2002-06-14/security_alert
  - url: >-
      https://web.archive.org/web/20020822025750/http://www.iss.net/security_center/static/9610.php
  - url: >-
      https://web.archive.org/web/20021206023914/http://rhn.redhat.com/errata/RHSA-2002-060.html
  - url: >-
      https://web.archive.org/web/20021223212650/http://online.securityfocus.com/bid/5812
  - url: >-
      https://web.archive.org/web/20070430090648/http://www.debian.org/security/2004/dsa-490
tags:
  - osv
  - pip
epss: 0.01439
epssPercentile: 0.71583
ingestedAt: '2026-07-08T18:25:46.815Z'
---

## Overview

ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.

## Affected packages

- `zope >= 2.4.0, < 2.6.0`

## Remediation

Upgrade to a patched release:

- `zope 2.6.0`
