CVE-2026-92570

Source
https://cve.org/CVERecord?id=CVE-2026-92570
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92570.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92570
Published
2026-09-16T14:40:49Z
Modified
2026-09-18T03:48:41Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
reNgine through 2.2.0 Unauthorized Configuration File Read
Details

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92570.json"
}
References

Affected packages

Git / github.com/yogeshojha/rengine

Affected ranges

Type
GIT
Repo
https://github.com/yogeshojha/rengine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.0"
        },
        {
            "fixed": "2.2.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.1
v0.2
v0.3
v0.5
v1.*
v1.0
v1.0.1
v1.0.2
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92570.json"