CVE-2026-54569
senaite.core5/100
exploitation likelihood
CVSS9.8
EPSS—
KEVNone
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission before resolving attacker
No EPSS/KEV signal · CVSS base 9.8
Public PoC / Exploit
No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.
References5