Sceawere
Vulnerability Detail
CVE-2026-105834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Rundeck Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 12h ago
- Vendor
- rundeck
- Product
- rundeck
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T13:16:46.597Z",
"pubdate": "2026-10-06T13:16:46.597Z",
"executiveSummary": "Rundeck versions prior to 6.2.0 are susceptible to a critical path traversal vulnerability involving improper input validation within the project configuration functionality.\nThe vulnerability allows an authenticated user, granted the 'project configure' Access Control List (ACL) permission, to read arbitrary files from the underlying server filesystem.\nThis flaw stems from the application failing to sanitize the 'resources.source.N.config.file' parameter, which accepts absolute file paths. An attacker can manipulate this field to bypass directory restrictions and access sensitive system files.\nThe impact is significant, as successful exploitation enables the retrieval of confidential configuration data, including database credentials, LDAP bind secrets, and proprietary information from other projects residing on the same instance.\nThe attack requires the attacker to possess specific project-level configuration privileges. Given the nature of the information exposed, this vulnerability poses a severe risk to the confidentiality and integrity of the Rundeck instance and its connected infrastructure.\nOrganizations using affected versions of Rundeck are advised to prioritize updating to version 6.2.0 or later to remediate the underlying flaw.",
"technicalDetails": "The vulnerability is rooted in an insecure implementation of the resource model source configuration handler within Rundeck. Specifically, the application fails to enforce path constraints when processing 'resources.source.N.config.file' configuration entries.\nAn authenticated user with the 'project configure' ACL can define or modify a resource model source. By injecting an absolute path into the 'file' configuration parameter, the application attempts to read the resource definition from the specified location on the server's disk.\nThe exploitation flow begins when an attacker accesses the project configuration interface. By setting the 'resources.source.N.config.file' parameter to an arbitrary absolute path (e.g., '/etc/passwd' or a sensitive configuration file containing database credentials), the attacker instructs the backend to treat the target file as a valid resource source.\nOnce the configuration is saved, the attacker interacts with the 'editProjectNodeSourceFile' function or the 'apiSourceGetContent' API endpoint. These components process the provided source configuration and return the contents of the target file to the user interface or API response, effectively bypassing intended access controls.\nBecause the system performs the read operation with the privileges of the service account running the Rundeck process, the attacker can extract any file readable by the Rundeck service, including but not limited to database connection strings, LDAP bind credentials, and sensitive project-specific data stored within the Rundeck home directory or system configuration paths.\nThis vulnerability is classified as an absolute path traversal because it allows the specification of root-relative paths, circumventing directory-level sanitization routines. The attack is effective because the system trusts user-supplied input in a privileged configuration context without secondary validation or canonicalization of the target path to ensure it resides within an authorized project directory.\nThe vulnerability affects all versions of Rundeck prior to 6.2.0. No specific network-level exposure is required beyond access to the web interface or API, as the primary constraint is the possession of project configuration credentials, making this a significant privilege escalation and information disclosure vector."
}