API Upload Endpoint Vulnerability in osuuu LightPicture
CVE-2026-6574
6.9MEDIUM
What is CVE-2026-6574?
A vulnerability is present in the osuuu LightPicture application, specifically affecting the API Upload Endpoint. This flaw allows for the manipulation of the installation SQL file, leading to hard-coded credentials being revealed. Attackers can exploit this issue remotely, potentially gaining unauthorized access to critical components of the application. The vendor was notified of this vulnerability but has yet to provide a response, heightening the risk for users operating on versions prior to 1.2.2.
Affected Version(s)
LightPicture 1.2.0
LightPicture 1.2.1
LightPicture 1.2.2
