PT-2026-93815 · Rengine · Rengine
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
reNgine versions prior to 2.2.1
Description
An authorization bypass exists in the 'GetFileContents' API endpoint. This issue allows any authenticated user, including those with low-privilege Auditor roles, to read bundled recon tool configuration files because the endpoint lacks role-based permission checks. This can lead to the exposure of third-party API keys for services such as SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge, and Hunter.
Recommendations
Update to a version newer than 2.2.0.
Restrict access to the 'GetFileContents' API endpoint to prevent unauthorized users from reading configuration files.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rengine