CVE-2026-105834
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary serv
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-22
Sin historial EPSS suficiente todavía.
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.
- github.comhttps://github.com/rundeck/rundeck
- github.comhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.java
- github.comhttps://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4
- github.comhttps://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4e
- github.comhttps://github.com/rundeck/rundeck/pull/10437
- github.comhttps://github.com/rundeck/rundeck/releases/tag/v6.2.0
- www.vulncheck.comhttps://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-397928.6 ALT—
———Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.9hCVE-2026-397546.5 MED—
———Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.9hCVE-2026-397527.7 ALT—
———Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.9hCVE-2026-105751——
——0Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.107.0 until 2.120.3, docling/backend/opendocument_backend.py uses the xlink:href attribute value of a draw:image element as a filesystem path when the referenced part is not found in the document archive. The _image_ref_from_odf_image function reads that attacker-controlled path without a scheme check, extraction-directory confinement, or the enable_local_fetch setting used by other backends. Readable files that Pillow can decode as images are embedded in converted output, and other existing paths can be distinguished through the attempted read. This issue is fixed in 2.120.3.22hCVE-2026-1057447.5 ALT—
——0Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \openin and \openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling the tikz_engine_allow_shell_escape option additionally permits shell commands through TeX. The default configuration, which does not enable Tectonic rendering, is not affected. This vulnerability is fixed in 2.132.0.22hCVE-2026-1022627.3 ALT—
——0Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.23h