PT-2026-67631 · Red Hat · Wildfly
CVE-2026-17614
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WildFly (affected versions not specified)
Description
A path traversal flaw exists in the domain mode implementation of WildFly. The
getFile() and getConfigurationFile() functions within LocalFileRepository in wildfly-core/deployment-repository fail to validate that resolved file paths remain within the configured repository or configuration root directories. A remote attacker who has compromised a slave host controller or obtained the slave host controller secret can use the slave-DC wire protocol to send crafted relative paths containing directory traversal sequences. This allows the Domain Controller to resolve and serve arbitrary files readable by the DC process, potentially leading to the unauthorized disclosure of system credentials, keystores, and configuration files.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wildfly