PT-2026-30896 · Pyload · Pyload

Offset

·

Published

2026-04-07

·

Updated

2026-05-15

·

CVE-2026-35586

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pyLoad versions prior to 0.5.0b3.dev97
Description pyLoad, a download manager written in Python, had an authorization issue in the set config value() function. The ADMIN ONLY CORE OPTIONS check used incorrect option names (ssl cert and ssl key) instead of the actual configuration option names (ssl certfile and ssl keyfile). This mismatch allowed users with SETTINGS permission to overwrite the SSL certificate and key file paths, bypassing the intended admin-only restriction. The ssl certchain option was also not included in the admin-only check.
Recommendations Update to version 0.5.0b3.dev97 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35586
GHSA-PPVX-RWH9-7RJ7
PYSEC-2026-123

Affected Products

Pyload