PT-2026-29597 · Pyload · Pyload

Denolfe

·

Published

2026-04-01

·

Updated

2026-04-02

·

CVE-2026-34749

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Payload versions prior to 3.79.1
Description A Cross-Site Request Forgery (CSRF) issue existed in the authentication process. In certain scenarios, the configured CSRF protection could be bypassed, enabling unauthorized cross-site requests. The serverURL configuration impacts whether a consumer is affected.
Recommendations Upgrade to version 3.79.1 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-34749
GHSA-P6MR-XF3R-GHQ4

Affected Products

Pyload