PT-2026-67631 · Red Hat · Wildfly

CVE-2026-17614

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WildFly (affected versions not specified)
Description A path traversal flaw exists in the domain mode implementation of WildFly. The getFile() and getConfigurationFile() functions within LocalFileRepository in wildfly-core/deployment-repository fail to validate that resolved file paths remain within the configured repository or configuration root directories. A remote attacker who has compromised a slave host controller or obtained the slave host controller secret can use the slave-DC wire protocol to send crafted relative paths containing directory traversal sequences. This allows the Domain Controller to resolve and serve arbitrary files readable by the DC process, potentially leading to the unauthorized disclosure of system credentials, keystores, and configuration files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17614

Affected Products

Wildfly