Description
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

PictShare versions prior to 3.7.1 expose a REST API endpoint that returns the complete raw metadata for any file, including a delete code, uploader IP, user agent, remote port, and hash. An unauthenticated attacker can call the API::info() endpoint to obtain this data, enabling the attacker to permanently delete files via the delete API and to expose uploader privacy and location data. The vulnerability is categorized as CWE‑522, Information Exposure.

Affected Systems

Affected systems are deployments of HaschekSolutions PictShare with any version earlier than 3.7.1. The product is identified by the vendor name HaschekSolutions.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Because the API is unauthenticated, the likely attack vector is remote over the network where the PictShare instance is exposed, allowing an attacker to retrieve sensitive data and delete arbitrary files without authorization.

Generated by OpenCVE AI on October 1, 2026 at 23:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PictShare to version 3.7.1 or later
  • Restrict access to the info and delete API endpoints with authentication or firewall rules
  • Implement monitoring of API logs to detect unauthorized info requests

Generated by OpenCVE AI on October 1, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Title PictShare < 3.7.1 Sensitive Information Disclosure via info API
First Time appeared Hascheksolutions
Hascheksolutions pictshare
Weaknesses CWE-522
CPEs cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:*
Vendors & Products Hascheksolutions
Hascheksolutions pictshare
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hascheksolutions Pictshare
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T21:08:37.900Z

Reserved: 2026-10-01T17:52:44.371Z

Link: CVE-2026-104051

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:00.833

Modified: 2026-10-01T22:17:00.833

Link: CVE-2026-104051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:30:14Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials