PT-2026-22019 · Loris · Loris

Guillaume Pillot

+1

·

Publicado

2026-02-25

·

Atualizado

2026-03-05

·

CVE-2026-26984

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LORIS versions prior to 26.0.5 LORIS versions prior to 27.0.2 LORIS versions prior to 28.0.0
Description LORIS is a self-hosted web application used for data and project management in neuroimaging research. An authenticated user with sufficient privileges can exploit a path traversal flaw to upload a malicious file to an arbitrary location on the server. Successful exploitation could lead to remote code execution (RCE). If the server is configured as read-only, RCE is not possible, but malicious file upload may still be achievable. The issue involves the ability to upload files via a path traversal, potentially impacting the server's integrity.
Recommendations Update LORIS to version 26.0.5 or later. Update LORIS to version 27.0.2 or later. Update LORIS to version 28.0.0 or later. If the media module is not in use, disable it as a workaround.

Exploit

Correção

RCE

Unrestricted File Upload

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26984
GHSA-MPGC-C48M-6V2H

Produtos afetados

Loris