Description
Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and cAccessControl.c, Python formatting can recursively access attributes and subscriptions using unrestricted getattr and getitem behavior instead of the policy-restricted getattr and getitem operations. A controlled format string can therefore disclose objects reachable from values available to the formatting operation. This issue is fixed in version 7.4.
Published: 2026-09-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Zope AccessControl, a security framework used by Zope applications, contains a flaw where Python's string formatting functions (str.format and str.format_map) can be abused when invoked on subclasses of str. The functions recursively traverse object attributes and subscriptions with unrestricted getattr and getitem operations, bypassing the framework's access policy. This permits a carefully crafted format string to reveal internal objects that are otherwise protected, leading to information disclosure. The weakness is classified as CWE-693, a failure to safeguard data that compromises confidentiality.

Affected Systems

The vulnerability exists in Zope Foundation's AccessControl component in all releases prior to 7.4. The fix was released in version 7.4, available as a patch on the project's GitHub releases page. Any Zope deployment that has not upgraded past 7.3 is potentially exposed, especially those that allow untrusted users to create or execute code that reaches these formatting functions.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, but the EPSS score of less than 1% suggests a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers would need to supply untrusted code or a malicious string subclass to trigger the vulnerable formatting path, which is typically an application-level threat rather than a network-level vector.

Generated by OpenCVE AI on September 18, 2026 at 02:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zope AccessControl to version 7.4 or later, where the format functions are correctly guarded against unrestricted attribute access.
  • If an immediate upgrade is not possible, restrict untrusted users from executing custom AccessControl code or from supplying string subclasses that invoke format or format_map.
  • Implement input validation that rejects format strings containing attribute or index references beyond a safe subset, preventing recursive dereferencing of protected objects.

Generated by OpenCVE AI on September 18, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pq59-9fq7-m886 Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Zope
Zope accesscontrol
Vendors & Products Zope
Zope accesscontrol

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and cAccessControl.c, Python formatting can recursively access attributes and subscriptions using unrestricted getattr and getitem behavior instead of the policy-restricted getattr and getitem operations. A controlled format string can therefore disclose objects reachable from values available to the formatting operation. This issue is fixed in version 7.4.
Title Zope AccessControl: Information disclosure through Python string `format` and `format_map` functions
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Zope Accesscontrol
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:35:46.823Z

Reserved: 2026-08-20T19:55:27.023Z

Link: CVE-2026-77401

cve-icon Vulnrichment

Updated: 2026-09-16T18:18:38.610Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:46.617

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-77401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure