CVE-2026-64826
rConfig < 8.2.13 Path Traversal File Read via FileDownloadController
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration.
| CWE | CWE-22 |
| Vendor | rconfig |
| Product | rconfig |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for rconfig rconfig
Be the first to know when new medium vulnerabilities affecting rconfig rconfig are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
rConfig / rConfig
0 < 8.2.13
References
github.com: https://github.com/rconfig/rconfig/releases/tag/core-8.2.13 github.com: https://github.com/rconfig/rconfig/pull/349 github.com: https://github.com/rconfig/rconfig/commit/d133a466a2df9d065177de9a8ed50f1bfe438aee vulncheck.com: https://www.vulncheck.com/advisories/rconfig-path-traversal-file-read-via-filedownloadcontroller
Credits
BENDIB MOHAMED ANIS VulnCheck