LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35463

CVE-2026-35463 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 7, 2026

pyLoad - Command Injection

Published: April 7, 2026Updated: April 7, 2026Remote Exploitable

Overview

pyLoad <= 0.5.0b3.dev96 contains a command injection caused by insufficient protection on plugin config options, letting non-admin users with SETTINGS permission execute arbitrary code via subprocess.Popen(), exploit requires SETTINGS permission.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Non-admin users with SETTINGS permission can execute arbitrary code remotely, potentially compromising the system.

Mitigation

Update to the latest version where plugin config options are properly protected.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 7, 2026

🟠 CVE-2026-35463 - High (8.8) pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to ad... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-35463/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 7, 2026

🟠 CVE-2026-35463 - High (8.8) pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to ad... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-35463/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-35463
Severity
High
CVSS Score
8.8
Type
command_injection
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days