{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-04T00:23:31Z",
  "bugzilla" : {
    "description" : "wildfly-core: Path Traversal on WildFly Domain Controller",
    "id" : "2507631",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2507631"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-22",
  "details" : [ "A path traversal flaw was found in WildFly's domain mode\nimplementation. The LocalFileRepository.getFile() and\ngetConfigurationFile() methods in\nwildfly-core/deployment-repository do not validate that the\nresolved file path remains within the configured repository or\nconfiguration root directories. A remote attacker who has\nobtained the slave host controller secret or compromised a slave\nhost controller can supply a crafted relative path containing\ndirectory traversal sequences (e.g., ../../etc/passwd) via the\nslave-DC wire protocol, causing the Domain Controller to resolve\nand serve arbitrary files readable by the DC process. This leads\nto unauthorized disclosure of sensitive information such as\nconfiguration files, keystores, and system credentials.", "A path traversal flaw was found in WildFly's domain mode\nimplementation. The LocalFileRepository.getFile() and\ngetConfigurationFile() methods in\nwildfly-core/deployment-repository do not validate that the\nresolved file path remains within the configured repository or\nconfiguration root directories. A remote attacker who has\nobtained the slave host controller secret or compromised a slave\nhost controller can supply a crafted relative path containing\ndirectory traversal sequences (e.g., ../../etc/passwd) via the\nslave-DC wire protocol, causing the Domain Controller to resolve\nand serve arbitrary files readable by the DC process. This leads\nto unauthorized disclosure of sensitive information such as\nconfiguration files, keystores, and system credentials." ],
  "statement" : "This Important vulnerability in WildFly domain mode allows an authenticated attacker, who has obtained the slave-secret credential, to perform arbitrary file reading on the Domain Controller's filesystem. This flaw bypasses intended access controls for file retrieval, potentially leading to sensitive information disclosure from the compromised host.",
  "acknowledgement" : "Red Hat would like to thank Kelvin Mbogo (@addcontent) for reporting this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "wildfly-deployment-repository",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Affected",
    "package_name" : "wildfly-deployment-repository",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Fix deferred",
    "package_name" : "wildfly-deployment-repository",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Fix deferred",
    "package_name" : "wildfly-deployment-repository",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-17614\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-17614" ],
  "name" : "CVE-2026-17614",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}