CVE-2026-77914: rConfig < 8.2.13 Core Path Traversal via Export Download Endpoint

Published Aug 24, 2026
·
Updated

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename parameter with traversal sequences to escape the intended export directory and access files outside it that are readable by the application process.

Affected Software

1 affected component
rConfig<8.2.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rConfig to a version that resolves this vulnerability.

    Fixed in 8.2.13
  2. Compensating control

    Until all affected instances are upgraded to rConfig 8.2.13, restrict access to the export download endpoint so only trusted authenticated users can reach it.

Event History

Aug 24, 2026
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated to rConfig and able to send requests to the export download endpoint. The attacker also needs to know or guess paths to files that are readable by the rConfig application process.

2

Are default deployments affected?

The provided information identifies rConfig versions before 8.2.13 as affected, but does not state whether the vulnerable export download endpoint is enabled or reachable in a default deployment.

3

What is the impact if exploitation succeeds?

The attacker can read arbitrary files outside the intended export directory, subject to the permissions of the rConfig application process. The supplied data describes confidentiality impact only; it does not indicate file modification or service disruption.

4

What can be done if upgrading is not immediately possible?

The provided information does not specify a workaround. Restrict access to rConfig and its export download endpoint to trusted authenticated users until the deployment can be updated to 8.2.13 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203