← Vulnerability feed

Vulnerability record · CVE-2026-34985 · published 8 April 2026

CVE-2026-34985: Mcgill loris insecure direct object reference vulnerability

Mcgill · Loris

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the backend was not applying access checks and it would be possible for someone who should not have access to a file to access it if they know the filename. This vulnerability is fixed in 27.0.3 and 28.0.1.

6.5 CVSS 3.1 Medium EPSS 0.27% · top 82.2% CWE-639 · Insecure direct object reference
6.5CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Jul 2026Last modified by NVD

Description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the backend was not applying access checks and it would be possible for someone who should not have access to a file to access it if they know the filename. This vulnerability is fixed in 27.0.3 and 28.0.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34985 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-26984Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 1.1%8.6CVE-2026-35446Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.38%7.5CVE-2026-33350Mcgill loris sql injection vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.41%7.5CVE-2026-34392Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.42%6.5CVE-2026-35165Mcgill loris insecure direct object reference vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%6.5CVE-2026-26985Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.52%6.1CVE-2026-39985Mcgill loris open redirect vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.35%5.4CVE-2026-35169Mcgill loris cross-site scripting vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-34985), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.