OVERVIEW: CVE-2026-41133 is an authorization bypass vulnerability affecting pyLoad, a free and open-source download manager written in Python, in versions up to and including 0.5.0b3.dev97. The vulnerability stems from the application caching user role and permission data in the session upon login and failing to refresh these values when administrators modify permissions in the database. This design flaw allows logged-in users to retain revoked privileges until session expiration or logout. SEVERITY: The vulnerability carries a HIGH severity rating with a CVSS score of 8.8 (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The attack is network-accessible with low complexity and requires only low privileges (an existing user login), making it practically exploitable. The impact is critical, enabling unauthorized access to confidential information, data modification, and system unavailability through retention of administrative capabilities. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and shows an extremely low EPSS score of 0.0003, indicating minimal practical exploitation probability. The vulnerability has generated limited community attention and remains inactive on security hot lists. A fix has been committed (e95804fb0d06cbb07d2ba380fc494d9ff89b68c1) and should be applied to affected installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-13CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.