Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files… (CVE-2026-105834)
Description
Rundeck versions prior to 6.2.0 have a path traversal vulnerability that allows users with project configure ACL permissions to read arbitrary files on the server. By setting a configuration parameter to an absolute file path, attackers can access sensitive data such as database passwords and LDAP credentials via specific API endpoints. This vulnerability has a CVSS score of 6.5, indicating a high severity risk.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105834 is a path traversal vulnerability in Rundeck before version 6.2.0. It permits users who have only the project configure ACL permission to read arbitrary files on the server by manipulating the resources.source.N.config.file parameter to specify any absolute path. The vulnerability can be exploited through the editProjectNodeSourceFile or apiSourceGetContent endpoints, enabling attackers to retrieve sensitive information including database passwords and LDAP bind credentials from other projects' data.
Potential Impact
An attacker with project configure ACL permissions can read arbitrary server files, potentially exposing sensitive credentials and configuration data. This can lead to unauthorized disclosure of confidential information, increasing the risk of further compromise. The vulnerability does not allow modification or denial of service but has a high confidentiality impact.
Mitigation Recommendations
A fix is available in Rundeck version 6.2.0 and later. Users should upgrade to version 6.2.0 or newer to remediate this vulnerability. No additional mitigation steps are indicated in the provided data.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3xjf-2x46-6jp7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-105834"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac523732cdf04f656c4bf34
Added to database: 10/06/2026, 16:36:03 UTC
Last enriched: 10/06/2026, 16:49:06 UTC
Last updated: 10/06/2026, 16:49:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.