CVE-2026-77401Medium· 6.8▾ SunlitZope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and cAccessControl.c, Python formatting can recursively access attributes and subscriptions using unrestricted getattr and getitem behavior instead of the policy-restricted getattr and getitem operations. A controlled format string can therefore disclose objects reachable from values available to the formatting operation. This issue is fixed in version 7.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
AccessControl < 7.4Patched in:
AccessControl 7.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-32807Medium· 4.4Remote Code Execution via unsafe classes in otherwise permitted modules
CVE-2024-51734Critical· 9.1Access control vulnerable to user data deletion by anonynmous users
CVE-2023-41050Medium· 6.8Information disclosure in AccessControl
CVE-2026-76825High· 8.4RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment
CVE-2026-53710Critical· 10.0MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs
CVE-2026-57120Medium· 6.5PraisonAI is a multi-agent teams system