GHSA-68W4-83FH-F2W8: GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng
GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng Vulnerability ID: GHSA-68W4-83FH-F2W8 CVSS Score: 8.8 Published: 2026-10-09 An authorization bypass and credential oracle vul
GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng
Vulnerability ID: GHSA-68W4-83FH-F2W8
CVSS Score: 8.8
Published: 2026-10-09
An authorization bypass and credential oracle vulnerability in pyload-ng allows authenticated users with minimal or no privileges to brute-force the administrator password. This is achieved through sensitive API methods exposed globally combined with a non-constant-time password hash comparison algorithm.
TL;DR
Low-privilege users can access administrative credential verification endpoints to brute-force the administrator password using a binary oracle and timing side-channel.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862, CWE-287, CWE-208
- Attack Vector: Network
- CVSS v3.1 Score: 8.8 (High)
- EPSS Score: N/A (No mapped CVE)
- Impact: Full Administrative Compromise / Configuration Arbitrary Manipulation
- Exploit Status: PoC (Proof of Concept) available
- CISA KEV Status: Not Listed
Affected Systems
- pyload-ng
- pyLoad download manager
-
pyload-ng: All versions prior to commit b99d2a2f06135363ceb0aab16aac5025f138e658 (Fixed in:
Commit b99d2a2f06135363ceb0aab16aac5025f138e658)
Code Analysis
Commit: b99d2a2
Fix getUserData permission level and introduce hmac.compare_digest to secure password verification against timing discrepancies.
Mitigation Strategies
- Upgrade pyload-ng to the latest version featuring the commit b99d2a2f06135363ceb0aab16aac5025f138e658.
- Implement network-level access controls to restrict access to the WebUI to trusted IP ranges.
- Deploy WAF rules to block access to getUserData and get_userdata endpoints for non-admin users.
Remediation Steps:
- Identify running pyload-ng instances in the network.
- Pull the latest version of pyload-ng from the repository or rebuild the package using the patched commit.
- Apply custom WAF rules to drop traffic matching '/api/getUserData' or '/api/get_userdata' requests from untrusted external sources.
- Perform a password rotation for all admin accounts in case of previous compromise.
References
Read the full report for GHSA-68W4-83FH-F2W8 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.