CVE-2026-35586General(pyload-ng_project / pyload-ng)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the ssl_certchain option was never added to the admin-only set at all. This vulnerability is fixed in 0.5.0b3.dev97.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload-ng

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
pyload-ng

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-07: 2Mentions · 2026-05-05: 1Technical Details · 2026-04-07: 104-0705-05
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure1General1
2026-05-051
General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🔴 pyload, Insecure Allowlist Bypass, #CVE-2026-35586 (Critical) https://dailycve.com/pyload-insecure-allowlist-bypass-cve-2026-35586-critical/

    Post summary

    The provided text announces a critical insecure allowlist bypass CVE for pyload but does not supply any technical, exploit, or patch information.

    0000037
    191 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35586 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses … https://www.cve.org/CVERecord?id=CVE-2026-35586 ----- Traducción: CVE-2026-35586 pyL… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-35586 in pyLoad, noting a pre-0.5.0b3.dev97 issue with ADMIN_ONLY_CORE_OPTIONS, but provides no PoC, exploit, or patch details.

    0000034
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35586 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses … https://www.cve.org/CVERecord?id=CVE-2026-35586

    Post summary

    The text merely lists the CVE reference without providing actionable details, evidence of exploitation, or remediation steps.

    00000147
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyload-ng_projectpyload-ng-python-

Explore more