Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104051— PictShare < 3.7.1 Sensitive Information Disclosure via info API

Quick assessment

Affected
HaschekSolutions pictshare
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PictShare 3.7.1 之前的版本存在一个信息泄露漏洞,允许未认证的攻击者通过调用 API::info() 端点获取秘密的 delete_code 和上传者元数据。该端点返回完整的原始元数据对象,而没有进行字段白名单过滤。攻击者可以利用公开可见的文件哈希,通过 info API 检索 delete_code,然后调用 delete API 永久删除任意文件。同时,该漏洞还会泄露上传者的 IP 地址、User Agent、远程端口以及 SHA-1 哈希值,从而导致内容完整性、可用性以及上传者隐私的丧失。

CVSS 8.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104051

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PictShare < 3.7.1 Sensitive Information Disclosure via info API
Source: CVE Program / CVE List V5
Vulnerability Description
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
HaschekSolutions pictshare 2.0.0 ~ 3.7.1 -

II. Public POCs for CVE-2026-104051

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104051

请登录查看更多情报信息。

Other References for CVE-2026-104051 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104051

No comments yet


Leave a comment