CVE-2026-26985Disclosure(mcgill / loris)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can read configuration files on the server by exploiting a path traversal vulnerability. Some of these files contain hard-coded credentials. The vulnerability allows an attacker to read configuration files containing hard-coded credentials. The attacker could then authenticate to the database or other services if those credentials are reused. The attacker must be authenticated and have the required permissions. However, the vulnerability is easy to exploit and the application source code is public. This problem is fixed in LORIS v26.0.5 and v27.0.2 and above, and v28.0.0 and above. As a workaround, the electrophysiogy_browser in LORIS can be disabled by an administrator using the module manager.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • loris

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
loris

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-26: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 102-2502-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-262
Disclosure1General1
Full discourse3 posts
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26985** pertains to a path traversal vulnerability in the LORIS (Longitudinal Online Research and Imaging System) web application, specifically affecting versions prior to 26.0.5, 27.0.2, and 28.0.0.0. This flaw allows an authenticated user with appropriate permissions to access server configuration files by exploiting a path traversal attack. Some of these configuration files contain sensitive hard-coded credentials, which, if accessed, could lead to further compromise of the system. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-26985

    Post summary

    The post announces CVE-2026-26985, a path traversal flaw in LORIS that allows authenticated users to read sensitive configuration files, potentially leading to further compromise.

    0100054
    20 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26985 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Startin… https://www.cve.org/CVERecord?id=CVE-2026-26985

    Post summary

    The text merely references the CVE record for LORIS without providing additional details.

    00000112
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26985 Authenticated Path Traversal in LORIS Exposing Configuration File Credentials https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26985

    Post summary

    The post announces CVE-2026-26985, an authenticated path traversal vulnerability in LORIS that exposes configuration file credentials, with no mention of PoC, exploit, patch, or active exploitation.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcgillloris---

Explore more