CVE-2026-33509: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33509 is an improper privilege management vulnerability (CWE-269) in pyLoad, an open-source download manager written in Python. A non-admin user granted the SETTINGS permission can execute arbitrary programs on the server as the pyLoad process user, effectively achieving remote code execution without administrative credentials. The vulnerability affects pyload-ng versions from 0.5.0a5.dev528 up to (but not including) 0.5.0b3.dev97, and pyload versions 0.4 through 0.4.20. It was published on March 20, 2026, with a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause is improper privilege management (CWE-269): the SETTINGS permission in pyLoad is documented as granting only the ability to "access settings," but in practice it allows users to invoke the set_config_value API endpoint to set a malicious reconnect script path (e.g., in the reconnect category under core). When pyLoad's reconnect feature triggers, the configured script is executed as the pyLoad process user, resulting in arbitrary code execution. Additionally, the get_config() API accessible to SETTINGS users exposes sensitive configuration values including proxy credentials and SSL key paths. The advisory provides concrete curl-based proof-of-concept steps demonstrating exploitation against a live pyLoad deployment (GitHub Advisory).

Impact

Successful exploitation allows a low-privileged user with only SETTINGS permission to achieve full remote code execution on the server, running arbitrary programs as the pyLoad process user. Beyond RCE, attackers can read sensitive configuration data including proxy credentials and SSL key paths via get_config(), disable SSL, change the bind address, redirect logging, and otherwise reconfigure security-critical network settings. The combination of credential exposure and arbitrary code execution creates significant risk for lateral movement and full host compromise (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available in the official GitHub security advisory, consisting of concrete curl commands that authenticate as a SETTINGS-permissioned user and set a malicious reconnect script path via the /api/set_config_value endpoint. The exploit requires only low-level privileges (a valid account with SETTINGS permission) and no user interaction, making it straightforward to weaponize. The EPSS score is approximately 0.063%, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the advisory date (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing pyLoad instances (default port 8000) running vulnerable versions (pyload-ng < 0.5.0b3.dev97 or pyload <= 0.4.20) using tools like Shodan or Censys.
  2. Authenticate as SETTINGS user: Obtain or use existing credentials for a non-admin account that has been granted the SETTINGS permission. Log in and capture the session cookie:
curl -c cookies.txt -X POST 'http://target:8000/api/login' -d 'username=settingsuser&password=password'
  1. Prepare malicious script: Place or upload a malicious shell script (e.g., /tmp/exploit.sh) on the server, or identify a writable path accessible to the pyLoad process. The script should contain the attacker's payload (e.g., a reverse shell).
  2. Set malicious reconnect script: Use the set_config_value API to configure the reconnect script path to the attacker-controlled script:
curl -b cookies.txt -X POST 'http://target:8000/api/set_config_value' \
  -d 'category=reconnect&option=script&value=/tmp/exploit.sh&section=core'
  1. Trigger execution: Trigger the reconnect feature (either by waiting for an automatic reconnect event or by invoking the relevant API call), causing pyLoad to execute the malicious script as the pyLoad process user.
  2. Achieve RCE / exfiltrate credentials: Collect the reverse shell or command output. Optionally, use get_config() to extract proxy credentials and SSL key paths for further lateral movement (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the pyLoad server process to unknown external IPs (potential reverse shell); unusual HTTP POST requests to /api/set_config_value with parameters category=reconnect&option=script.
  • Logs: pyLoad access logs showing POST requests to /api/set_config_value or /api/get_config from non-admin user sessions; log entries showing execution of unexpected scripts during reconnect events.
  • File System: Presence of unexpected shell scripts (e.g., /tmp/exploit.sh or similar) on the server; new or modified files in world-writable directories created around the time of suspicious API calls.
  • Process: Unexpected child processes spawned by the pyLoad Python process (e.g., /bin/bash, curl, wget, nc, python) that are not part of normal pyLoad operation (GitHub Advisory).

Mitigation and workarounds

Update pyload-ng to version 0.5.0b3.dev97 or later, or update pyload to version 0.4.21 or later to receive the patch (commit f5e284fcdfeaf08436bb03e5fcf697aaac659d8b). As an immediate workaround, restrict the SETTINGS permission to only fully trusted administrative users, since this permission was not originally intended to grant code execution capability. Audit all existing accounts with SETTINGS permission to verify they are legitimate and necessary, and review pyLoad configuration for any unexpected reconnect script paths (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management