CVE-2026-104051

🟡 Monitoruj

W PictShare przed 3.7.1 ujawnienie informacji pozwala na usunięcie plików przez nieautoryzowanych użytkowników.

CVSS
8.2
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-10-01 22:17:00 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:47:49 UTC
Referencje