CVE-2026-35446
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neur
CVSS
7.7
High
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: Apr 8, 2026 · Last modified: Jul 24, 2026 · CWE-552
0.2%EPSS · 30 days0.2%
2026-06-302026-07-26
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping the intended download directories. This vulnerability is fixed in 27.0.3 and 28.0.1.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-579907.4 HIG—
——0Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.22hCVE-2026-153426.5 MED13.4%
——4Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.4dCVE-2026-597037.5 HIG31.2%
——9repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, permitting attackers to supply file:// scheme URLs that bypass validation and are passed directly to git clone, enabling unauthorized access to all tracked file contents on the server filesystem.17dCVE-2025-147719.9 CRI27.3%
——8Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.5dCVE-2026-455435.3 MED18.9%
——6Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.5dCVE-2026-404255.7 MED30.2%
——9The administrator account for the
Danelec MacGregor Voyage Data Recorder
web interface can directly edit sensitive files related to authentication, potentially changing the root password.7d