CVE-2026-26984Disclosure(mcgill / loris)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with sufficient privileges can exploit a path traversal vulnerability to upload a malicious file to an arbitrary location on the server. Once uploaded, the file can be used to achieve remote code execution (RCE). An attacker must be authenticated and have the appropriate permissions to exploit this issue. If the server is configured as read-only, remote code execution (RCE) is not possible; however, the malicious file upload may still be achievable. This problem is fixed in LORIS v26.0.5 and above, v27.0.2 and above, and v28.0.0 and above. As a workaround, LORIS administrators can disable the media module if it is not being used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • loris

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
loris

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-26: 2Technical Details · 2026-02-26: 102-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26984 Authenticated Path Traversal in LORIS Enabling Arbitrary File Upload and RCE https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26984

    Post summary

    The text announces CVE‑2026‑26984, describing an authenticated path traversal vulnerability in LORIS that allows arbitrary file upload and remote code execution.

    0001046
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26984 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior t… https://www.cve.org/CVERecord?id=CVE-2026-26984

    Post summary

    The text only references the CVE and the affected application without additional details.

    00000114
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcgillloris---

Explore more