PT-2026-22025 · Loris · Loris

Guillaume Pillot

+1

·

Publicado

2026-02-25

·

Atualizado

2026-03-05

·

CVE-2026-26985

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LORIS versions prior to 26.0.5 LORIS versions prior to 27.0.2 LORIS versions prior to 28.0.0
Description LORIS is a self-hosted web application used for data and project management in neuroimaging research. An authenticated user with appropriate authorization can read server configuration files through a path traversal issue. These files may contain hard-coded credentials that could be reused for authentication to the database or other services. The application source code is publicly available, and the issue is considered easy to exploit. The vulnerability allows access to configuration files containing hard-coded credentials.
Recommendations LORIS versions prior to 26.0.5 should be updated to version 26.0.5 or later. LORIS versions prior to 27.0.2 should be updated to version 27.0.2 or later. LORIS versions prior to 28.0.0 should be updated to version 28.0.0 or later. As a workaround, an administrator can disable the electrophysiology browser module using the module manager.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26985
GHSA-G3PP-RQVQ-XXHP

Produtos afetados

Loris