PT-2026-31426 · Loris · Loris

CVE-2026-35165

·

Published

2026-04-08

·

Updated

2026-04-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LORIS versions 21.0.0 through 27.0.2 and 28.0.0
Description LORIS is a self-hosted web application for neuroimaging research data and project management. A flaw exists where the backend endpoint did not properly verify file access permissions while the frontend was restricting access. This could allow a user to download files they are not authorized to access if they know or can determine the filename.
Recommendations Update to version 27.0.3 or 28.0.1

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35165
GHSA-QP6X-QFX7-54WP

Affected Products

Loris