CVE-2026-92570
reNgine through 2.2.0 Unauthorized Configuration File Read
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.
| CWE | CWE-862 |
| Vendor | yogeshojha |
| Product | rengine |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for yogeshojha rengine
Be the first to know when new medium vulnerabilities affecting yogeshojha rengine are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
yogeshojha / rengine
0 โค 2.2.0
References
github.com: https://github.com/yogeshojha/rengine/issues/1554 github.com: https://github.com/yogeshojha/rengine github.com: https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/api/views.py#L1607-L1700 github.com: https://github.com/yogeshojha/rengine/blob/302b5f32e7aa5958fec9e405772f4aa069eb21a2/web/reNgine/settings.py#L129-L141 vulncheck.com: https://www.vulncheck.com/advisories/rengine-through-2.2.0-unauthorized-configuration-file-read
Credits
๐ George Chen