Generated remediation guidance and an executive summary. No account required.
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config options, not to plugin config options. The AntiVirus plugin stores an executable path (avfile) in its config, which is passed directly to subprocess.Popen(). A non-admin user with SETTINGS permission can change this path to achieve remote code execution.
Cite this page
CVE-2026-35463. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-35463
Use CWE-78, Pyload-Ng Project vendor hub and Pyload-Ng product page to widen CVE-2026-35463 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-54802, CVE-2026-35459 and CVE-2026-33511 for nearby disclosures in the same product family.