MEDIUM

CVE-2026-92570

2026-09-16 CVSS v3.1
CVSS
6.5

Description

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE