CVE-2026-104051
Received Received - Intake

PictShare Information Disclosure via Unauthenticated API Access

Vulnerability report for CVE-2026-104051, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pictshare pictshare to 3.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PictShare before version 3.7.1 has an information disclosure flaw where unauthenticated attackers can access sensitive metadata via the API::info() endpoint. This endpoint returns raw metadata including secret delete codes and uploader details without proper restrictions. Attackers can use file hashes to retrieve delete codes and delete files permanently, while also exposing uploader IP addresses, user agents, ports, and SHA-1 hashes.

Detection Guidance

Check if the PictShare API endpoint /api/info is accessible without authentication. Use curl commands like: curl -X GET http://<target>/api/info to see if it returns sensitive metadata including delete_code and uploader details.

Impact Analysis

This vulnerability allows attackers to delete your files permanently by exploiting exposed delete codes. It also reveals sensitive uploader information like IP addresses and user agents, compromising privacy. Files may become unavailable, and content integrity is at risk due to unauthorized deletions.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data (uploader IPs, user agents) and potential data deletion. HIPAA compliance may be affected if protected health information is stored and deleted. Organizations could face fines for failing to protect sensitive data and ensure availability.

Mitigation Strategies

Upgrade PictShare to version 3.7.1 or later to patch the vulnerability. If immediate upgrade is not possible, restrict access to the /api/info endpoint via network rules or web application firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104051. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart