Junglewise Threat Intelligence

CVE-2026-77914: rConfig Core path traversal in export download endpoint

CVE-2026-77914 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Executive brief

rConfig is a network device configuration management platform. An authenticated user can exploit a path traversal vulnerability in the export download feature to read arbitrary files on the server that are accessible to the application process, such as configuration files or sensitive application data. No remote code execution or file writing capability exists.

Technical details

The vulnerability is a path traversal (directory traversal / CWE-22) flaw in the export download endpoint of rConfig V8 Core. The vulnerable component fails to properly validate and constrain filenames supplied by authenticated users, allowing directory traversal sequences (e.g., ../) to escape the intended export directory. An authenticated attacker can manipulate the filename parameter to access arbitrary files readable by the application process, resulting in unauthorized information disclosure. The fix, available in version 8.2.13, adds filename validation and enforces that resolved file paths remain within the designated export directory, with regression testing added to prevent recurrence.

Affected products

  • rConfig Core 8.0.0 before 8.2.13

Timeline

  • 2026-08-10: disclosed: Security release version 8.2.13 published with fix
  • 2026-08-10: advisory: GitHub Security Advisory GHSA-m5rw-jcrm-mmwc published
  • 2026-08-10: patched: Version 8.2.13 contains the patch; prior versions 8.0.0–8.2.12 affected

References