PT-2026-104019 · Pictshare · Pictshare

·

CVE-2026-104051

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions PictShare versions prior to 3.7.1
Description An information disclosure issue exists where unauthenticated attackers can obtain the secret delete code and uploader metadata. This occurs when calling the 'API::info()' endpoint, which returns the complete raw metadata object without a field whitelist. By using a publicly visible file hash, an attacker can retrieve the delete code and subsequently use the delete API to permanently remove arbitrary files. Additionally, this exposes the uploader IP, User Agent, remote port, and SHA-1 hash, compromising content integrity, availability, and uploader privacy.
Recommendations Update PictShare to version 3.7.1 or later. Restrict access to the 'API::info()' endpoint to minimize the risk of metadata exposure.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104051

Affected Products

Pictshare