PT-2026-30896 · Pyload · Pyload
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-35586
CVSS v3.1
6.8
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN ONLY CORE OPTIONS authorization set in set config value() uses incorrect option names ssl cert and ssl key, while the actual configuration option names are ssl certfile and ssl keyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the ssl certchain option was never added to the admin-only set at all. This vulnerability is fixed in 0.5.0b3.dev97.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload