{"id":"CVE-2026-40071","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-40071","summary":"pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce…","details":"pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execute MODIFY operations that should be denied by pyLoad's own permission model. This vulnerability is fixed in 0.5.0b3.dev97.","published":"2026-04-09T18:17:03.367","modified":"2026-06-17T10:44:41.217","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"},"epss":{"score":0.00219,"percentile":0.1241,"asOf":"2026-08-04"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://github.com/pyload/pyload/security/advisories/GHSA-rfgh-63mg-8pwm"},{"type":"EXPLOIT","url":"https://github.com/pyload/pyload/security/advisories/GHSA-rfgh-63mg-8pwm"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T10:44:41.217"}}