Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35463

30
FAUCET Score

pyLoad, a Python-based download manager, contains a privilege escalation vulnerability (CVE-2026-35463) in versions 0.5.0b3.dev96 and earlier. The flaw exists in the AntiVirus plugin configuration, which fails to enforce the ADMIN_ONLY_OPTIONS protection mechanism that normally restricts access to security-critical settings. A non-admin user with SETTINGS permission can modify the executable path parameter (avfile) and achieve remote code execution when the plugin executes this unsanitized input via subprocess.Popen(). The vulnerability carries a CVSS score of 8.8 (HIGH), indicating severe risk with low attack complexity and no user interaction required. An attacker requires only low-level privileges (SETTINGS permission) and network access to exploit this flaw, resulting in complete system compromise with high confidentiality, integrity, and availability impact. The FAUCET Risk Score of 52.0/100 reflects the significant but not critical threat level. Currently, CVE-2026-35463 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The extremely low EPSS score (0.00103) suggests minimal real-world exploitation probability at this time. However, given the straightforward nature of the attack and the high CVSS rating, organizations running affected pyLoad versions should prioritize patching to prevent potential abuse by internal or compromised accounts.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.5.0b3.dev96CPE matchmatch criteria
cpe:2.3:a:pyload-ng_project:pyload-ng:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.81%
Probability of exploitation in next 30 days
EPSS Percentile
53.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0081 is in the 48th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-w48f-wwwf-f5frhigh

pyLoad: Improper Neutralization of Special Elements used in an OS Command

Apr 4, 2026

References

github.com / pyload/pyload/commit/c4cf995a2803bdbe388addfc2b0f323277efc0e1
Patch
github.com / pyload/pyload/security/advisories/GHSA-w48f-wwwf-f5fr
ExploitMitigationVendor Advisory