pyLoad, a Python-based download manager, contains a privilege escalation vulnerability (CVE-2026-35463) in versions 0.5.0b3.dev96 and earlier. The flaw exists in the AntiVirus plugin configuration, which fails to enforce the ADMIN_ONLY_OPTIONS protection mechanism that normally restricts access to security-critical settings. A non-admin user with SETTINGS permission can modify the executable path parameter (avfile) and achieve remote code execution when the plugin executes this unsanitized input via subprocess.Popen(). The vulnerability carries a CVSS score of 8.8 (HIGH), indicating severe risk with low attack complexity and no user interaction required. An attacker requires only low-level privileges (SETTINGS permission) and network access to exploit this flaw, resulting in complete system compromise with high confidentiality, integrity, and availability impact. The FAUCET Risk Score of 52.0/100 reflects the significant but not critical threat level. Currently, CVE-2026-35463 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The extremely low EPSS score (0.00103) suggests minimal real-world exploitation probability at this time. However, given the straightforward nature of the attack and the high CVSS rating, organizations running affected pyLoad versions should prioritize patching to prevent potential abuse by internal or compromised accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.0b3.dev96CPE matchmatch criteria | cpe:2.3:a:pyload-ng_project:pyload-ng:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.