
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33509 is an improper privilege management vulnerability (CWE-269) in pyLoad, an open-source download manager written in Python. A non-admin user granted the SETTINGS permission can execute arbitrary programs on the server as the pyLoad process user, effectively achieving remote code execution without administrative credentials. The vulnerability affects pyload-ng versions from 0.5.0a5.dev528 up to (but not including) 0.5.0b3.dev97, and pyload versions 0.4 through 0.4.20. It was published on March 20, 2026, with a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is improper privilege management (CWE-269): the SETTINGS permission in pyLoad is documented as granting only the ability to "access settings," but in practice it allows users to invoke the set_config_value API endpoint to set a malicious reconnect script path (e.g., in the reconnect category under core). When pyLoad's reconnect feature triggers, the configured script is executed as the pyLoad process user, resulting in arbitrary code execution. Additionally, the get_config() API accessible to SETTINGS users exposes sensitive configuration values including proxy credentials and SSL key paths. The advisory provides concrete curl-based proof-of-concept steps demonstrating exploitation against a live pyLoad deployment (GitHub Advisory).
Successful exploitation allows a low-privileged user with only SETTINGS permission to achieve full remote code execution on the server, running arbitrary programs as the pyLoad process user. Beyond RCE, attackers can read sensitive configuration data including proxy credentials and SSL key paths via get_config(), disable SSL, change the bind address, redirect logging, and otherwise reconfigure security-critical network settings. The combination of credential exposure and arbitrary code execution creates significant risk for lateral movement and full host compromise (GitHub Advisory, Feedly).
A proof-of-concept exploit is publicly available in the official GitHub security advisory, consisting of concrete curl commands that authenticate as a SETTINGS-permissioned user and set a malicious reconnect script path via the /api/set_config_value endpoint. The exploit requires only low-level privileges (a valid account with SETTINGS permission) and no user interaction, making it straightforward to weaponize. The EPSS score is approximately 0.063%, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the advisory date (GitHub Advisory).
curl -c cookies.txt -X POST 'http://target:8000/api/login' -d 'username=settingsuser&password=password'/tmp/exploit.sh) on the server, or identify a writable path accessible to the pyLoad process. The script should contain the attacker's payload (e.g., a reverse shell).set_config_value API to configure the reconnect script path to the attacker-controlled script:curl -b cookies.txt -X POST 'http://target:8000/api/set_config_value' \
-d 'category=reconnect&option=script&value=/tmp/exploit.sh§ion=core'get_config() to extract proxy credentials and SSL key paths for further lateral movement (GitHub Advisory)./api/set_config_value with parameters category=reconnect&option=script./api/set_config_value or /api/get_config from non-admin user sessions; log entries showing execution of unexpected scripts during reconnect events./tmp/exploit.sh or similar) on the server; new or modified files in world-writable directories created around the time of suspicious API calls./bin/bash, curl, wget, nc, python) that are not part of normal pyLoad operation (GitHub Advisory).Update pyload-ng to version 0.5.0b3.dev97 or later, or update pyload to version 0.4.21 or later to receive the patch (commit f5e284fcdfeaf08436bb03e5fcf697aaac659d8b). As an immediate workaround, restrict the SETTINGS permission to only fully trusted administrative users, since this permission was not originally intended to grant code execution capability. Audit all existing accounts with SETTINGS permission to verify they are legitimate and necessary, and review pyLoad configuration for any unexpected reconnect script paths (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."