CVE-2026-54569

senaite.core
5/100
exploitation likelihood
CVSS9.8
EPSS
KEVNone
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission before resolving attacker
No EPSS/KEV signal · CVSS base 9.8
Public PoC / Exploit

No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.

References5