Path Traversal Vulnerability in WildFly by Red Hat
CVE-2026-17614
4.4MEDIUM
Key Information:
What is CVE-2026-17614?
A vulnerability exists in the WildFly domain mode implementation, where the LocalFileRepository methods fail to validate file paths properly. This flaw allows a remote attacker, who has gained access to the slave host controller secret or compromised a slave controller, to craft a relative path with directory traversal sequences. Through the slave-DC wire protocol, the attacker could exploit this vulnerability to make the Domain Controller resolve and serve unauthorized files. As a result, sensitive information, including configuration files, keystores, and system credentials, may be disclosed, posing a significant threat to the integrity of the system.
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Kelvin Mbogo (@addcontent) for reporting this issue.