CVE-2026-104051: PictShare < 3.7.1 Sensitive Information Disclosure via info API

Published Oct 1, 2026
·
Updated

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret deletecode and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the deletecode via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.

Affected Software

1 affected component
PictShare PictShare<3.7.1

Event History

Oct 1, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker can exploit it. The attacker needs a publicly visible file hash to query the info API endpoint.

2

What information and impact result from exploitation?

The endpoint can disclose the secret delete_code along with uploader metadata including IP address, User Agent, remote port, and SHA-1 hash. An attacker who obtains the delete_code can call the delete API to permanently delete files.

3

Which deployments are affected?

PictShare versions before 3.7.1 are affected. The described attack does not require authentication or user interaction.

4

How can I determine whether a file may be exposed?

A file may be exposed if its hash is publicly visible and the instance runs a version before 3.7.1. In that condition, the info API can return the file's raw metadata object, including the delete_code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203