PT-2026-22025 · Loris · Loris
Guillaume Pillot
+1
·
Published
2026-02-25
·
Updated
2026-03-05
·
CVE-2026-26985
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LORIS versions prior to 26.0.5
LORIS versions prior to 27.0.2
LORIS versions prior to 28.0.0
Description
LORIS is a self-hosted web application used for data and project management in neuroimaging research. An authenticated user with appropriate authorization can read server configuration files through a path traversal issue. These files may contain hard-coded credentials that could be reused for authentication to the database or other services. The application source code is publicly available, and the issue is considered easy to exploit. The vulnerability allows access to configuration files containing hard-coded credentials.
Recommendations
LORIS versions prior to 26.0.5 should be updated to version 26.0.5 or later.
LORIS versions prior to 27.0.2 should be updated to version 27.0.2 or later.
LORIS versions prior to 28.0.0 should be updated to version 28.0.0 or later.
As a workaround, an administrator can disable the electrophysiology browser module using the module manager.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loris