VDB
Sign up
—

PYSEC-2026-755

ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions

Quick fix

PYSEC-2026-755 — zope: upgrade to the fixed version with the command below.

pip install --upgrade 'zope>=2.6.0'

Details

ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/zope
Introduced in: 2.4.0Fixed in: 2.6.0
Fixpip install --upgrade 'zope>=2.6.0'

References