Executive brief
WildFly is an open-source Java application server widely used in enterprise environments. A path traversal vulnerability in the domain mode implementation allows attackers who have compromised a slave host controller to read arbitrary files on the Domain Controller, potentially exposing sensitive configuration files, keystores, and system credentials.
Technical details
The vulnerability exists in the LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository, which fail to validate that resolved file paths remain within configured repository or configuration directories. A remote attacker with the slave host controller secret or who has compromised a slave host controller can supply a crafted relative path containing directory traversal sequences (e.g., ../../etc/passwd) via the slave-DC wire protocol. The Domain Controller will then resolve and serve arbitrary files readable by the DC process. No patch availability information is provided in the advisory.
Affected products
- Red Hat WildFly <UNKNOWN>
Timeline
- 2026-08-04: disclosed