Junglewise Threat Intelligence

CVE-2026-40071: pyload-ng improper authorization in WebUI JSON endpoints

CVE-2026-40071 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Technologies: pyLoad Next Generation, pyload-ng (PyPI). Vendors: pyLoad, PyPI.

Executive brief

pyload-ng, a popular open-source download manager, contains a flaw in how it checks user permissions within its web interface. This allows users who are only supposed to add or delete items to perform restricted management tasks, such as reordering the download queue or stopping active downloads. While this does not allow a full account takeover, it enables unauthorized users to disrupt operations and modify the organization of files.

Technical details

A permission mismatch exists between the pyload-ng WebUI JSON endpoints and the core API. Specifically, endpoints such as /json/package_order, /json/link_order, and /json/abort_link use @login_required decorators with 'ADD' or 'DELETE' permissions, whereas the underlying core API methods (order_package, order_file, and stop_downloads) require 'MODIFY' permissions. An authenticated attacker with low-level privileges can exploit these endpoints to perform unauthorized actions, leading to horizontal privilege escalation. This results in an integrity impact via queue reordering and an availability impact via the unauthorized termination of active downloads. As of the advisory, no patched version is specified beyond the vulnerable range of <= 0.5.0b3.

Affected products

  • pyload pyload-ng <= 0.5.0b3

Timeline

  • 2026-04-08: advisory: GitHub Advisory published
  • 2026-04-09: disclosed: NVD publication date

References

Related threats