Loading market data...
← Back to CVE feed

CVE-2026-92570

MEDIUM CVSS 6.5 View on NVD ↗

Description

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 16, 2026 15:19 UTC Modified: Sep 16, 2026 15:19 UTC