Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35464

26
FAUCET Score

CVE-2026-35464 is a privilege escalation vulnerability in pyLoad, an open-source Python download manager, that allows authenticated users with SETTINGS and ADD permissions to achieve arbitrary code execution. The vulnerability exploits a gap in the security controls implemented to fix a previous vulnerability, specifically the failure to restrict the storage_folder configuration option that can be manipulated to redirect downloads to the Flask session directory. The attack has a HIGH severity rating with CVSS 3.1 score of 7.5, requiring network access and low-level user privileges but achievable with relatively low complexity. An attacker with the noted permissions can plant a malicious pickle payload as a predictable session file and trigger code execution when a corresponding session cookie is presented, resulting in high impact to confidentiality, integrity, and availability. There is currently no indication of active exploitation in the wild. The vulnerability has not been added to the KEV Catalog or designated as a priority on vulnerability hot lists, and the EPSS score of 0.0009 indicates minimal real-world exploitation activity relative to other known vulnerabilities. The issue has been patched via commit c4cf995a2803bdbe388addfc2b0f323277efc0e1, and organizations running pyLoad should prioritize updating to the patched version.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026-04-02CPE matchmatch criteria
cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 35th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-4744-96p5-mp2jhigh

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

Apr 4, 2026

References

github.com / pyload/pyload/commit/c4cf995a2803bdbe388addfc2b0f323277efc0e1
Patch
github.com / pyload/pyload/security/advisories/GHSA-4744-96p5-mp2j
ExploitMitigationVendor Advisory
github.com / pyload/pyload/security/advisories/GHSA-r7mc-x6x7-cqxx
ExploitVendor Advisory
cve.org / CVERecord
Third Party Advisory