CVE-2026-45306
📛 CVE Title
(no title)
Description
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.5 / 10
- CVSS vector
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N- Effective score
- 6.5 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45306
NVD / KEV / EPSS data refreshed 2026-05-25 00:04 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32958 - Assigner
- GitHub_M
- Published
- May 28, 2026, 5:12:59 PM
- Updated
- May 28, 2026, 6:49:45 PM
- EUVD base score (CVSS 3.1)
-
6.5 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N - EUVD-reported EPSS
- 0.2300
- Vendors
- pyload
- Products
-
pyload (< 0.5.0b3.dev100)
- Aliases
-
GHSA-w727-595x-pc3r
ENISA description: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session directory (/tmp/pyLoad/flask). An authenticated attacker can set storage_folder to the session directory and download session files of other users via /files/get/, leading to account takeover. This vulnerability is fixed in 0.5.0b3.dev100.
EUVD references (1)
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (4)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/pyload/pyload/security/advisories/GHSA-w727-595x-pc3r tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45306 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45306 tenable:www.cve.org
Remediations (10)
-
web:blog.qualys.com
Microsoft has rolled out its March 2026 Patch Tuesday updates, delivering a fresh batch of security fixes designed to keep Windows environments protected from emerging threats.
2026-05-26 03:07 UTC -
web:cheatsheetseries.owasp.org
Virtual Patching Cheat Sheet Introduction The goal with this cheat Sheet is to present a concise virtual patching framework that organizations can follow to maximize the timely implementation of mitigation protections. Definition: Virtual Patching A security policy enforcement layer which prevents and reports the exploitation attempt of a known vulnerability. The virtual patch works when the ...
2026-05-26 03:07 UTC -
web:community.ui.com
Published: May 21, 2026 Updated: May 22, 2026 Version: 1.1 Revision: 1.1 Summary 1 of 5 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. Affected Products: UniFi OS Server (Version 5.0.6 and earlier) Mitigation : Update your UniFi OS Server to Version 5.0.8 or later ...
2026-05-26 03:07 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-26 03:07 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-26 03:07 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-26 03:07 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-26 03:07 UTC -
web:www.lansweeper.com
The March 2026 edition of Patch Tuesday brings us 88 fixes, with 3 rated as critical. We've listed the most important changes below. Microsoft Excel Information Disclosure Vulnerability CVE - 2026 -26144 is a critical information disclosure flaw in Microsoft Excel caused by improper input neutralization during web page generation.
2026-05-26 03:07 UTC -
web:www.linkedin.com
Microsoft has released its March 2026 Patch Tuesday security updates, addressing 79 vulnerabilities across multiple products, including two publicly disclosed zero-day flaws and several high ...
2026-05-26 03:07 UTC -
web:www.penligent.ai
Second, chipset and OEM dependencies make remediation slower and messier than software-only patching. Google's bulletin explains the two Android patch levels for March 2026 and clarifies that devices with security patch levels of 2026 -03-01 or 2026 -03-05 are protected against the associated issues, depending on applicable components.
2026-05-26 03:07 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.