---
id: CVE-2026-77914
title: >-
  rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that
  allows authenticated users to read arbitrary files by supplying crafted
  filenames containing directory traversal sequences to the export download
  endpoint
summary: >-
  rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that
  allows authenticated users to read arbitrary files by supplying crafted
  filenames containing directory traversal sequences to the export download
  endpoint. Att…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-24'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:14:58.577'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77914'
references:
  - url: 'https://github.com/rconfig/rconfig/releases/tag/core-8.2.13'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rconfig/rconfig/security/advisories/GHSA-m5rw-jcrm-mmwc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rconfig-v8-core-path-traversal-via-export-download-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00717
epssPercentile: 0.51755
ingestedAt: '2026-09-23T18:29:33.085Z'
---

## Overview

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename parameter with traversal sequences to escape the intended export directory and access files outside it that are readable by the application process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
