PT-2026-48501 · Pypi+1 · Picklescan+1

·

CVE-2026-3490

·

Published

2026-03-03

·

Updated

2026-06-29

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 1.0.4 UniFi OS Server (affected versions not specified)
Description picklescan fails to block pkgutil.resolve name, which allows attackers to bypass the blocklist by resolving dangerous functions through indirect REDUCE calls. This enables remote attackers to invoke blocked functions such as os.system, builtins.exec, or subprocess.call to achieve remote code execution.
UniFi OS Server contains an improper access control flaw where nginx evaluates the raw request URI for authentication but routes using the normalized URI. This allows unauthenticated attackers to reach protected endpoints and chain the issue into full root remote code execution.
Recommendations Update picklescan to version 1.0.4 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability regarding UniFi OS Server.

Exploit

Fix

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3490
GHSA-82FG-2R99-H7V6
GHSA-VVPJ-8CMC-GX39
PYSEC-2026-456

Affected Products

Unifi Os Server
Picklescan