U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-17614

Change History

New CVE Received from Red Hat, Inc. 8/03/2026 11:16:25 PM

Action Type Old Value New Value
Added Description

                  
                
              
A path traversal flaw was found in WildFly's domain mode
  implementation. The LocalFileRepository.getFile() and
  getConfigurationFile() methods in
  wildfly-core/deployment-repository do not validate that the
  resolved file path remains within the configured repository or
  configuration root directories. A remote attacker who has
  obtained the slave host controller secret or compromised a slave
  host controller can supply a crafted relative path containing
  directory traversal sequences (e.g., ../../etc/passwd) via the
  slave-DC wire protocol, causing the Domain Controller to resolve
  and serve arbitrary files readable by the DC process. This leads
  to unauthorized disclosure of sensitive information such as
  configuration files, keystores, and system credentials.
Added CVSS V3.1

                  
                
              
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Added CWE

                  
                
              
CWE-22
Added Reference

                  
                
              
https://access.redhat.com/security/cve/CVE-2026-17614
Added Reference

                  
                
              
https://bugzilla.redhat.com/show_bug.cgi?id=2507631
Added Affected

                  
                
              
[{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-deployment-repository","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-deployment-repository","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform Expansion Pack","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-deployment-repository","cpes":["cpe:/a:redhat:jbosseapxp"]},{"vendor":"Red Hat","product":"Red Hat Single Sign-On 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-deployment-repository","cpes":["cpe:/a:redhat:red_hat_single_sign_on:7"]}]