External risk intelligence

Plone Classic Portlet Template Injection Leading to Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-57149

This vulnerability affects Plone, a content management system typically deployed as a public-facing web application. Since the vulnerability is exploitable via the web interface by authenticated users, it is commonly accessible in typical internet-facing web deployments.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue in Plone's portlet functionality could allow authenticated users to execute arbitrary code on the server, potentially leading to unauthorized access or modification of the Plone site. This vulnerability stems from how user-provided templates in Classic portlets were processed, enabling an attacker to bypass security controls.

  • User input can run unauthorized code.
  • Affects web content management systems.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An authenticated user can exploit this vulnerability by configuring a Classic portlet with a malicious input. This input is processed as a TALES path expression, allowing the attacker to execute arbitrary code on the server. The vulnerability essentially allows a regular user to escalate their privileges to that of the Plone process.

  • Attacker needs portlet configuration access.
  • User-supplied template/macro fields.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

A user able to configure a Classic portlet could execute arbitrary code on the server. This could lead to a privilege escalation, allowing an authenticated user to gain elevated access to the Plone process.

  • Server-side code execution is at risk.
  • Exploitable via authenticated user interaction.
  • Full server compromise is a realistic consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary responsibility for addressing this vulnerability typically falls on the Application Owner or Platform Team managing the Plone instance, in coordination with the Security Team for exposure assessment and Vendor Management if a vendor-supplied solution is in place. The immediate first step is to identify all Plone instances, confirm their accessibility and business criticality, and then determine the accountable owner for each instance before planning remediation or implementing workarounds.

  • Identify Plone instances and ownership.
  • Verify portlet management access and exposure.
  • Plan remediation or implement documented workarounds.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is plone.app.portlets in the context of Plone?

Plone is an open-source content management system used to build websites and intranets. The plone.app.portlets component provides the interface for managing portlets—those functional blocks or widgets that appear on the side of a page, such as search tools, login forms, or navigation menus—that help organize and display site content.

What does CWE-95 mean for CVE-2026-57149?

CWE-95 refers to Improper Neutralization of Directives in Dynamically Evaluated Code, commonly known as Code Injection. In this CVE, the Classic portlet feature incorrectly processed user-supplied text as a TALES expression. Because the software evaluated this input as a command rather than plain text, a user could inject code that the server then executes.

How is this code execution vulnerability triggered?

An attacker triggers this by adding or editing a Classic portlet within the Plone interface. By inserting a crafted TALES path expression into the template or macro fields, they force the system to evaluate that input as code. This vulnerability is not triggered by simply viewing a page or interacting with standard site navigation; it requires the ability to configure these specific portlet settings.

Is my instance relevant according to Halo Surface Signal?

Yes, Halo Surface Signal flags this as likely relevant because Plone is frequently deployed as a public-facing web application. Since the vulnerability is exploitable through the web interface, any internet-facing installation where users have permission to configure portlets presents a clear path for exploitation.

What are the first steps to secure my Plone installation?

First, identify all active Plone instances and their business owners. Prioritize updating the plone.app.portlets package to version 5.0.8, 6.0.4, or 7.0.2. If an immediate update is not feasible, restrict portlet management permissions to trusted administrators only, or unregister the Classic portlet component entirely to remove the attack surface.

References