CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-17614

mediumCVSS 4.4covered by 1 sourcefirst seen 2026-08-04
A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the configured repository or configuration root directories. A remote attacker who has obtained the slave host controller secret or compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol, causing the Domain Controller to resolve and serve arbitrary files readable by the DC process. This leads to unauthorized disclosure of sensitive information such as configuration files, keystores, and system credentials.

⚡ Watch CVE-2026-17614

Get an email if CVE-2026-17614 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-17614

CVE.org record

Embed the live status

CVE-2026-17614 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-17614 status](https://www.csirts.com/badge/CVE-2026-17614)](https://www.csirts.com/cve/CVE-2026-17614)