HIGH
yogeshojha
CVE published 2026-09-16
CVE-2026-92570
CVE-2026-92570 is an authorization bypass vulnerability in reNgine through 2.2.0 that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys by querying the GetFileContents API endpoint without role-based permission checks. This vulnerability allows authenticated users to read configuration f [truncated]