Sceawere

Vulnerability Detail

CVE-2026-104051UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PictShare Unauthenticated Information Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
1d ago
Vendor
HaschekSolutions
Product
pictshare
Attack Type
Insufficiently Protected Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-01T22:17:00.833Z",
  "pubdate": "2026-10-01T22:17:00.833Z",
  "executiveSummary": "PictShare versions prior to 3.7.1 are susceptible to an information disclosure vulnerability within the API::info() endpoint. This flaw stems from a lack of input validation and field filtering during the metadata retrieval process, causing the application to return the entire raw metadata object to the requester.\nBy targeting this endpoint, unauthenticated attackers can extract sensitive data, including secret delete_code strings and comprehensive uploader metadata. The disclosure of these values facilitates unauthorized file deletion and the exposure of personally identifiable information (PII).\nThe risk is categorized as critical, as the vulnerability requires no authentication and allows remote attackers to compromise system availability and user privacy. Successful exploitation leads to the loss of content integrity via unauthorized file removal and the compromise of uploader anonymity through the leak of IP addresses, User Agents, and remote port information.",
  "technicalDetails": "The vulnerability resides in the API::info() function of the PictShare application. The root cause is an insecure implementation of data exposure where the system returns the complete, unfiltered raw metadata object associated with an uploaded file when queried via the API.\nUnder normal operations, the API is intended to provide status information regarding a file. However, the current implementation fails to enforce a field whitelist, resulting in the inclusion of sensitive backend fields, specifically the 'delete_code', which is intended to be known only by the content uploader.\nThe attack flow proceeds as follows: First, an attacker identifies a target file hash, which is publicly accessible as part of the file URL structure. Second, the attacker invokes the API::info() endpoint, passing the file hash as a parameter. Third, the application processes the request and responds with a JSON object containing the full metadata. This object includes the 'delete_code', as well as sensitive uploader information such as the uploader's IP address, User Agent string, remote port, and the SHA-1 hash of the file.\nOnce the 'delete_code' is obtained, the attacker can move to the second phase of exploitation: unauthorized file deletion. By invoking the delete API and providing the previously harvested 'delete_code', the attacker can trigger the removal of the file from the server. This constitutes a permanent loss of content integrity and system availability. Furthermore, the systematic collection of uploader metadata poses a significant privacy risk, as it allows for the deanonymization and tracking of users who have interacted with the platform.\nThis vulnerability is classified as an unauthenticated information disclosure and broken access control issue. Because the application logic does not distinguish between the creator of the content and an unauthenticated third party when executing the info() function, the entire metadata payload is exposed to any network-capable actor. There are no privilege requirements or authentication vectors needed to intercept this information, making it highly exploitable over the network."
}
CVE-2026-104051: PictShare Unauthenticated Information Disclosure Vulnerability (HIGH Severity, CVSS: 8.2) | Sceawere