CVE-2026-34985Disclosure(mcgill / loris)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the backend was not applying access checks and it would be possible for someone who should not have access to a file to access it if they know the filename. This vulnerability is fixed in 27.0.3 and 28.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • loris

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
loris

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Technical Details · 2026-04-09: 104-0804-09
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-091
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34985 Unauthorized File Access in LORIS Neuroimaging System Versions 16... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34985 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet only announces CVE‑2026‑34985, noting unauthorized file access in LORIS, without providing PoC, exploit, mitigation, or exploitation evidence.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34985 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16… https://www.cve.org/CVERecord?id=CVE-2026-34985

    Post summary

    The text simply references the CVE-2026-34985 identifier for the LORIS application without providing exploitation, patch, or technical detail information.

    0000082
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmcgillloris---
Appmcgillloris28.0.0--

Explore more