API Upload Endpoint Vulnerability in osuuu LightPicture
CVE-2026-6574

6.9MEDIUM

Key Information:

Vendor

Osuuu

Vendor
CVE Published:
19 April 2026

What is CVE-2026-6574?

A vulnerability is present in the osuuu LightPicture application, specifically affecting the API Upload Endpoint. This flaw allows for the manipulation of the installation SQL file, leading to hard-coded credentials being revealed. Attackers can exploit this issue remotely, potentially gaining unauthorized access to critical components of the application. The vendor was notified of this vulnerability but has yet to provide a response, heightening the risk for users operating on versions prior to 1.2.2.

Affected Version(s)

LightPicture 1.2.0

LightPicture 1.2.1

LightPicture 1.2.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vulnplusbot (VulDB User)
VulDB CNA Team
.