PULSE
FEED
ransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Services
← All CVEs
CVE WatchOct 6, 2026

CVE-2026-105834

Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary serv

CVSS

6.5

Medium

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-22

EPSS · 30d

Not enough EPSS history yet.

Technical description

Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-863609.6 CRI
—
———Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.56m
CVE-2026-711687.3 HIG
—
———Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.56m
CVE-2026-106109—
—
———Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe trusted configuration can delete data writable by the build user before compilation begins. No attacker-controlled input reaches build.distDir by default, so exploitation requires compromised or less-trusted automation to influence build configuration, or a developer to run a mistaken configuration. This issue is fixed in version 3.3.0.51m
CVE-2026-1061037.1 HIG
—
———Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.51m
CVE-2026-1058658.1 HIG
—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.51m
CVE-2026-1057953.1 LOW
—
———Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.3h