Junglewise Threat Intelligence

CVE-2026-35165: aces LORIS authorization bypass in document_repository

CVE-2026-35165 · Severity: medium · CVSS 6.3 · Published 2026-04-08

Executive brief

LORIS, a web-based platform for managing neuroimaging research data, contains a security flaw in its document repository. While the user interface appears to restrict file access, the underlying system does not properly verify permissions when a file is requested directly. This could allow an authorized user to download sensitive research documents they are not permitted to see if they can guess or determine the specific filename.

Technical details

An authorization bypass vulnerability (CWE-639) exists in the LORIS document_repository module. The root cause is a discrepancy between frontend access controls and backend enforcement; specifically, the backend endpoint failed to verify if the requesting user had the appropriate site-level permissions for a requested file. An authenticated attacker with low privileges can exploit this by sending direct network requests to the backend API. By guessing or brute-forcing filenames, the attacker can bypass intended access restrictions to download unauthorized files. The issue is resolved in versions 27.0.3 and 28.0.1 by implementing server-side checks that validate the user's CenterID against the file's metadata in the database.

Affected products

  • aces LORIS (Longitudinal Online Research and Imaging System) >= 21.0.0, < 27.0.3; >= 28.0.0, < 28.0.1

Timeline

  • 2026-04-08: advisory: Original GitHub Security Advisory published
  • 2026-04-08: patched: Fixes released in versions 27.0.3 and 28.0.1

References