PT-2026-80922 · Rconfig · Rconfig

·

CVE-2026-77914

·

Published

2026-08-24

·

Updated

2026-09-06

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rConfig versions prior to 8.2.13
Description Authenticated users can read arbitrary files by providing crafted filenames containing directory traversal sequences to the export download endpoint. By manipulating the filename parameter, an attacker can escape the intended export directory and access files outside of it that are readable by the application process. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 8.2.13 or later. Avoid using the filename parameter in the export download endpoint until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77914
GHSA-M5RW-JCRM-MMWC

Affected Products

Rconfig