Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data. | |
| Title | Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T12:57:51.615Z
Reserved: 2026-10-05T22:00:10.841Z
Link: CVE-2026-105834
No data.
Status : Received
Published: 2026-10-06T13:16:46.597
Modified: 2026-10-06T13:16:46.597
Link: CVE-2026-105834
No data.
OpenCVE Enrichment
No data.