๐Ÿ” CVE Alert

CVE-2026-105834

MEDIUM 6.5

Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.

CWE CWE-22
Vendor rundeck
Product rundeck
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for rundeck rundeck

Be the first to know when new medium vulnerabilities affecting rundeck rundeck are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

rundeck / rundeck
0 < 6.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rundeck/rundeck/pull/10437 github.com: https://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4e github.com: https://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4 github.com: https://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.java github.com: https://github.com/rundeck/rundeck/releases/tag/v6.2.0 github.com: https://github.com/rundeck/rundeck vulncheck.com: https://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source

Credits

Eldor Nabijonov