๐Ÿ” CVE Alert

CVE-2026-104051

HIGH 8.2

PictShare < 3.7.1 Sensitive Information Disclosure via info API

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.

CWE CWE-522
Vendor hascheksolutions
Product pictshare
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for hascheksolutions pictshare

Be the first to know when new high vulnerabilities affecting hascheksolutions pictshare are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High

Affected Versions

HaschekSolutions / pictshare
2.0.0 < 3.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3 github.com: https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1 vulncheck.com: https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api

Credits

Alisher Qarshibayev VulnCheck