CVE-2026-105834
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary serv
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-22
Not enough EPSS history yet.
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.
- github.comhttps://github.com/rundeck/rundeck
- github.comhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.java
- github.comhttps://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4
- github.comhttps://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4e
- github.comhttps://github.com/rundeck/rundeck/pull/10437
- github.comhttps://github.com/rundeck/rundeck/releases/tag/v6.2.0
- www.vulncheck.comhttps://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-863609.6 CRI—
———Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.56mCVE-2026-711687.3 HIG—
———Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.56mCVE-2026-106109——
———Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe trusted configuration can delete data writable by the build user before compilation begins. No attacker-controlled input reaches build.distDir by default, so exploitation requires compromised or less-trusted automation to influence build configuration, or a developer to run a mistaken configuration. This issue is fixed in version 3.3.0.51mCVE-2026-1061037.1 HIG—
———Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1.51mCVE-2026-1058658.1 HIG—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.51mCVE-2026-1057953.1 LOW—
———Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.3h