{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-104051/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pictshare:pictshare:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-104051"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=6CFCB492-25F8-5848-B5DF-C73516A62F1F\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["PictShare (\u003c 3.7.1)"],"_cs_severities":["high"],"_cs_tags":["information-disclosure","api-vulnerability","cve-2026-104051"],"_cs_type":"advisory","_cs_vendors":["PictShare","Haschek Solutions"],"content_html":"\u003cp\u003ePictShare versions prior to 3.7.1 contain an information disclosure vulnerability in the API::info() endpoint. The application fails to implement a field whitelist when returning metadata objects via this API. As a result, unauthenticated attackers can supply a file hash to the endpoint to retrieve the complete metadata object. This object contains highly sensitive information, including the secret 'delete_code', the original uploader's IP address, User Agent string, remote port, and the file's SHA-1 hash. The exposure of the 'delete_code' presents a significant security risk, as an attacker can use this value to invoke the application's delete API to permanently remove arbitrary files from the server, leading to a loss of data integrity and system availability. Defenders should prioritize patching this vulnerability by upgrading to version 3.7.1 or later.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target PictShare instance accessible over the network.\u003c/li\u003e\n\u003cli\u003eAttacker gathers publicly accessible file hashes from the application's front-end or through reconnaissance.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP GET or POST request to the API::info() endpoint, including a target file hash in the request parameters.\u003c/li\u003e\n\u003cli\u003eThe application processes the request and returns the full, unfiltered metadata object associated with the hash to the unauthenticated attacker.\u003c/li\u003e\n\u003cli\u003eAttacker parses the JSON or raw response to extract the 'delete_code' and sensitive uploader metadata (IP, User Agent).\u003c/li\u003e\n\u003cli\u003eAttacker sends a secondary request to the application's delete API endpoint, providing the extracted 'delete_code'.\u003c/li\u003e\n\u003cli\u003eThe application validates the 'delete_code' and proceeds to permanently delete the requested file.\u003c/li\u003e\n\u003cli\u003eSuccessful deletion results in a permanent loss of content availability and potential privacy impact for the original uploader.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized information disclosure of user metadata and the ability for unauthenticated attackers to perform arbitrary file deletions. This compromises both user privacy and the availability of data hosted on the affected PictShare instance. The vulnerability carries a CVSS v3.1 base score of 8.2, reflecting its severity in environments where data availability is critical.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all PictShare instances to version 3.7.1 or later immediately to address CVE-2026-104051.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to restrict exposure of the PictShare API endpoints to untrusted networks.\u003c/li\u003e\n\u003cli\u003eReview web server logs for high volumes of requests to the API::info() endpoint followed by requests to the delete API, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T11:34:30Z","date_published":"2026-10-01T22:18:36Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pictshare-info-disclosure/","summary":"PictShare versions prior to 3.7.1 are vulnerable to an unauthenticated information disclosure flaw in the API::info() endpoint, allowing attackers to retrieve sensitive metadata and delete arbitrary files.","title":"Information Disclosure and Unauthorized File Deletion in PictShare","url":"https://feed.craftedsignal.io/briefs/2026-10-pictshare-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-104051","version":"https://jsonfeed.org/version/1.1"}