Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

GHSA-68W4-83FH-F2W8: GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng

GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng Vulnerability ID: GHSA-68W4-83FH-F2W8 CVSS Score: 8.8 Published: 2026-10-09 An authorization bypass and credential oracle vul

GHSA-68W4-83FH-F2W8: Privilege Escalation and Administrative Password Oracle in pyLoad-ng

Vulnerability ID: GHSA-68W4-83FH-F2W8
CVSS Score: 8.8
Published: 2026-10-09

An authorization bypass and credential oracle vulnerability in pyload-ng allows authenticated users with minimal or no privileges to brute-force the administrator password. This is achieved through sensitive API methods exposed globally combined with a non-constant-time password hash comparison algorithm.

TL;DR

Low-privilege users can access administrative credential verification endpoints to brute-force the administrator password using a binary oracle and timing side-channel.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862, CWE-287, CWE-208
  • Attack Vector: Network
  • CVSS v3.1 Score: 8.8 (High)
  • EPSS Score: N/A (No mapped CVE)
  • Impact: Full Administrative Compromise / Configuration Arbitrary Manipulation
  • Exploit Status: PoC (Proof of Concept) available
  • CISA KEV Status: Not Listed

Affected Systems

  • pyload-ng
  • pyLoad download manager
  • pyload-ng: All versions prior to commit b99d2a2f06135363ceb0aab16aac5025f138e658 (Fixed in: Commit b99d2a2f06135363ceb0aab16aac5025f138e658)

Code Analysis

Commit: b99d2a2

Fix getUserData permission level and introduce hmac.compare_digest to secure password verification against timing discrepancies.

Mitigation Strategies

  • Upgrade pyload-ng to the latest version featuring the commit b99d2a2f06135363ceb0aab16aac5025f138e658.
  • Implement network-level access controls to restrict access to the WebUI to trusted IP ranges.
  • Deploy WAF rules to block access to getUserData and get_userdata endpoints for non-admin users.

Remediation Steps:

  1. Identify running pyload-ng instances in the network.
  2. Pull the latest version of pyload-ng from the repository or rebuild the package using the patched commit.
  3. Apply custom WAF rules to drop traffic matching '/api/getUserData' or '/api/get_userdata' requests from untrusted external sources.
  4. Perform a password rotation for all admin accounts in case of previous compromise.

References

Read the full report for GHSA-68W4-83FH-F2W8 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.