cvedb.io
CVE-2026-35586
MEDIUM · CVSS 6.8
EPSS exploitation probability: 0%
Published 2026-04-07T17:16:34.140 · Last modified 2026-06-17T10:40:49.300

Summary

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the ssl_certchain option was never added to the admin-only set at all. This vulnerability is fixed in 0.5.0b3.dev97.

Affected products

pyload-ng_project — pyload-ng

Does this affect you?

Add your gear to cvedb and we'll alert you only when pyload-ng_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.