<Vulnerability name="CVE-2026-17614">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-04T00:23:31</PublicDate>
    <Bugzilla id="2507631" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507631" xml:lang="en:us">
wildfly-core: Path Traversal on WildFly Domain Controller
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
A path traversal flaw was found in WildFly's domain mode
  implementation. The LocalFileRepository.getFile() and
  getConfigurationFile() methods in
  wildfly-core/deployment-repository do not validate that the
  resolved file path remains within the configured repository or
  configuration root directories. A remote attacker who has
  obtained the slave host controller secret or compromised a slave
  host controller can supply a crafted relative path containing
  directory traversal sequences (e.g., ../../etc/passwd) via the
  slave-DC wire protocol, causing the Domain Controller to resolve
  and serve arbitrary files readable by the DC process. This leads
  to unauthorized disclosure of sensitive information such as
  configuration files, keystores, and system credentials.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A path traversal flaw was found in WildFly's domain mode
  implementation. The LocalFileRepository.getFile() and
  getConfigurationFile() methods in
  wildfly-core/deployment-repository do not validate that the
  resolved file path remains within the configured repository or
  configuration root directories. A remote attacker who has
  obtained the slave host controller secret or compromised a slave
  host controller can supply a crafted relative path containing
  directory traversal sequences (e.g., ../../etc/passwd) via the
  slave-DC wire protocol, causing the Domain Controller to resolve
  and serve arbitrary files readable by the DC process. This leads
  to unauthorized disclosure of sensitive information such as
  configuration files, keystores, and system credentials.
    </Details>
    <Statement xml:lang="en:us">
This Important vulnerability in WildFly domain mode allows an authenticated attacker, who has obtained the slave-secret credential, to perform arbitrary file reading on the Domain Controller's filesystem. This flaw bypasses intended access controls for file retrieval, potentially leading to sensitive information disclosure from the compromised host.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank Kelvin Mbogo (@addcontent) for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wildfly-deployment-repository</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:8">
        <ProductName>Red Hat JBoss Enterprise Application Platform 8</ProductName>
        <FixState>Affected</FixState>
        <PackageName>wildfly-deployment-repository</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wildfly-deployment-repository</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_single_sign_on:7">
        <ProductName>Red Hat Single Sign-On 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wildfly-deployment-repository</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-17614
https://nvd.nist.gov/vuln/detail/CVE-2026-17614
    </References>
</Vulnerability>