CVE-2026-6574 Details
Description
A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in osuuu LightPicture versions through 1.2.2, specifically in the API Upload Endpoint. The issue arises from a hard-coded secret key written into the database during the installation process. This key is used as the sole authentication method for sensitive API actions, such as uploading and deleting files. As a result, an unauthenticated attacker can exploit this vulnerability to perform administrative tasks without a valid session or token.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 19, 2026CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/790000 | [email protected] | Technical Description |
| https://vuldb.com/vuln/358209 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/358209/cti | [email protected] | AdvisoryPermission Required |
| https://vulnplus-note.wetolink.com/share/VhoNkMja5u7A | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| osuuu LightPicture | <= 1.2.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 19, 2026 | New CVE Received | [email protected] |
Volerion