CVE ID :CVE-2026-44888 Published : May 27, 2026, 8:16 p.m. | 12ย hours, 8ย minutes ago Description :Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into pialert.conf without validation. Since pialert.conf is loaded via Python's exec()
Unauthenticated RCE via
Exploit
CVE-2026-44888
MITRE CVE High
Refer to CVE-2026-44888 NVD advisory