CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-105487: A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability security flaw

CVE-2026-105487. CVSS base score 6.5 (MEDIUM, Vendor/CNA).

Affected technology

reNgine · 2.0, 2.1, 2.2.0
yogeshojha

Description’s affected range: up to 2.2.0

Component: listTargets Endpoint
Function: subdomain_discovery
File: web/reNgine/tasks.py

Attack conditions (VulDB, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-77, CWE-78
CCR priority
26.0 /100 (P4)
CVSS
6.5 /10 · AV:N/AC:L/Au:S/C:P/I:P/A:P · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-105487.html