Red Hat WildFly: path traversal
Medium4.4CVE-2026-17614 · Published Aug 4, 2026 · updated Aug 6, 2026
A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat JBoss Enterprise Application Platform 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | Red Hat SSSD: out-of-bounds read | Medium5.5 | No fix yet |
| Aug 4 | Red Hat Enterprise Linux 10: server-side request forgery | Medium5.4 | 5.80 |
| Aug 4 | Red Hat Enterprise Linux 10: out-of-bounds read | Medium6.5 | 5.80 |
| Aug 4 | Red Hat Build of Keycloak: improper signature check | Low3.7 | No fix yet |
| Aug 4 | Red Hat popt: code execution | Low2.5 | No fix yet |
| Aug 4 | Red Hat SSSD: uninitialized resource | Low3.3 | No fix yet |