CVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repos
A path traversal flaw was found in WildFly's domain mode
implementation. The LocalFileRepository.getFile() and
getConfigurationFile() methods in
wildfly-core/deployment-repository do not validate that the
resolved file path remains within the configured repository or
configuration root directories. A remote attacker who has
obtained the slave host controller secret or compromised a slave
host controller can supply a crafted relative path containing
directory traversal sequences (e.g., ../../etc/passwd) via the
slave-DC wire protocol, causing the Domain Controller to resolve
and serve arbitrary files readable by the DC process. This leads
to unauthorized disclosure of sensitive information such as
configuration files, keystores, and system credentials.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-17614
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17614 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A path traversal
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-56845: An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when Custom…nvd · 2026-08-04
- unknownCVE-2026-67970: Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attack…nvd · 2026-08-03
- highCVE-2026-61372: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability i…nvd · 2026-08-03
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…nvd · 2026-08-03
- highCVE-2026-69089: Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which pas…nvd · 2026-08-03
- highCVE-2026-69086: SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attr…nvd · 2026-08-03
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04
- mediumCVE-2026-58045: A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion …2026-08-04