---
id: CVE-2026-105834
title: >-
  Rundeck before 6.2.0 contains a path traversal vulnerability that allows users
  holding only the project configure ACL to read arbitrary server files by
  setting resources.source.N.config.file to any absolute path
summary: >-
  Rundeck before 6.2.0 contains a path traversal vulnerability that allows users
  holding only the project configure ACL to read arbitrary server files by
  setting resources.source.N.config.file to any absolute path. Attackers can
  retrieve f…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: rundeck
product: rundeck
affected:
  - rundeck < 6.2.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T16:00:36.547'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105834'
references:
  - url: 'https://github.com/rundeck/rundeck'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.java
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4e
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/pull/10437'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/releases/tag/v6.2.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T14:00:19.131Z'
---

## Overview

Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
