VDB
Sign up
CRITICAL9.1

PYSEC-2026-2076

Access control vulnerable to user data deletion by anonynmous users

Quick fix

PYSEC-2026-2076 — zope: upgrade to the fixed version with the command below.

pip install --upgrade 'zope>=5.11.1'

Details

### Impact Anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access.

### Patches The problem is fixed in version 7.2.

### Workarounds The problem can be fixed by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.

### References https://github.com/zopefoundation/AccessControl/issues/159

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/zope
Introduced in: 0Fixed in: 5.11.1
Fixpip install --upgrade 'zope>=5.11.1'

References