Path Traversal Vulnerability in Pulpcore by Red Hat
CVE-2026-12701

9CRITICAL

What is CVE-2026-12701?

A path traversal vulnerability exists in Pulpcore, specifically in the relative_path_validator function. This function incorrectly validates content paths by only ensuring they do not start with a '/' character, thus inadequately addressing directory traversal sequences such as '../'. With this flaw, an authenticated administrator can exploit relative_path variables to incorporate traversal sequences that can navigate outside the intended export directory during FilesystemExport operations. Since the uploaded file content can also be controlled by the user, this vulnerability permits arbitrary file writes to any writable location by the Pulp service user, posing a significant risk of service compromise or enabling further system exploitation.

Affected Version(s)

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.49.63-2.el8ap

Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:3.49.63-2.el9ap

Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:3.49.63-2.el9ap

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Martin Brodeur (Independent security researcher) for reporting this issue.
.