Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rundeck
Rundeck rundeck |
|
| Vendors & Products |
Rundeck
Rundeck rundeck |
Tue, 06 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data. | |
| Title | Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T16:13:38.357Z
Reserved: 2026-10-05T22:00:10.841Z
Link: CVE-2026-105834
Updated: 2026-10-06T16:13:35.027Z
Status : Awaiting Analysis
Published: 2026-10-06T13:16:46.597
Modified: 2026-10-06T17:17:19.303
Link: CVE-2026-105834
No data.
OpenCVE Enrichment
Updated: 2026-10-07T07:15:07Z
