CVE-2024-51734Critical· 9.1▾ MidnightAccess control vulnerable to user data deletion by anonynmous users
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Anonymous users can delete the user data maintained by an AccessControl.userfolder.UserFolder which may prevent any privileged access.
The problem is fixed in version 7.2.
The problem can be fixed by adding data__roles__ = () to AccessControl.userfolder.UserFolder.
https://github.com/zopefoundation/AccessControl/issues/159
accesscontrol < 7.2zope < 5.11.1Upgrade to a patched release:
accesscontrol 7.2zope 5.11.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77401Medium· 6.8Zope AccessControl provides a general security framework for use in Zope
CVE-2021-32807Medium· 4.4Remote Code Execution via unsafe classes in otherwise permitted modules
CVE-2023-41050Medium· 6.8Information disclosure in AccessControl