CVE-2026-92570
6.5 MEDIUMpublic exploit availablePublished 2026-09-16 · Updated 2026-09-18
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-862
Public exploit & PoC references
- https://github.com/yogeshojha/rengine
- https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/api/views.py#L1607-L1700
- https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/reNgine/settings.py#L129-L141
- https://github.com/yogeshojha/rengine/issues/1554
- https://github.com/yogeshojha/rengine/issues/1554
All references
- https://github.com/yogeshojha/rengine
- https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/api/views.py#L1607-L1700
- https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/reNgine/settings.py#L129-L141
- https://github.com/yogeshojha/rengine/issues/1554
- https://www.vulncheck.com/advisories/rengine-through-2.2.0-unauthorized-configuration-file-read
- https://github.com/yogeshojha/rengine/issues/1554
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-14484
- MEDIUMCVE-2025-14486
- MEDIUMCVE-2025-14487
- MEDIUMCVE-2026-11899
- HIGHCVE-2026-12000
- UNSCOREDCVE-2026-13227PoC
- UNSCOREDCVE-2026-13229PoC
- MEDIUMCVE-2026-15946
Related by shared AI tags and CWE weakness class. Browse the full archive.