PT-2026-30896 · Pyload · Pyload

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35586

CVSS v3.1

6.8

Medium

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN ONLY CORE OPTIONS authorization set in set config value() uses incorrect option names ssl cert and ssl key, while the actual configuration option names are ssl certfile and ssl keyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the ssl certchain option was never added to the admin-only set at all. This vulnerability is fixed in 0.5.0b3.dev97.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35586

Affected Products

Pyload