MEDIUM
CVE-2026-92570
CVSS
6.5
Description
reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.34%
Probability of exploitation in next 30 days
27.7th percentile
References
https://github.com/yogeshojha/rengine
https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/api/views.py#L1607-L1700
https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/reNgine/settings.py#L129-L141
https://github.com/yogeshojha/rengine/issues/1554
https://www.vulncheck.com/advisories/rengine-through-2.2.0-unauthorized-configuration-file-read
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.