PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy. | |
| Title | PictShare < 3.7.1 Sensitive Information Disclosure via info API | |
| First Time appeared |
Hascheksolutions
Hascheksolutions pictshare |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hascheksolutions
Hascheksolutions pictshare |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T21:08:37.900Z
Reserved: 2026-10-01T17:52:44.371Z
Link: CVE-2026-104051
No data.
Status : Received
Published: 2026-10-01T22:17:00.833
Modified: 2026-10-01T22:17:00.833
Link: CVE-2026-104051
No data.
OpenCVE Enrichment
No data.
Weaknesses