
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64826 is a path traversal vulnerability in rConfig, an open-source network configuration management tool, affecting all versions before 8.2.13. The flaw resides in the download_export() method of FileDownloadController, which concatenates an unsanitized filename GET parameter directly onto the export base path, allowing authenticated attackers to read arbitrary files accessible to the web server process. It was published on August 12, 2026, with a patch released on August 10, 2026 in version 8.2.13. The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (Github Advisory, Feedly).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where FileDownloadController::download_export() built its file path by directly concatenating the raw filename query parameter onto export_path() with no sanitization: $path = export_path() . $_GET['filename']. An authenticated attacker can supply ../ sequences (or URL-encoded variants such as ..%2F, or doubled-dot forms like ....//) in the filename parameter to escape the exports directory and access any file readable by the web server process. The fix, introduced in PR #349, switches to the Laravel Request object, reduces the filename through basename(), and uses realpath() to confirm the resolved path is a real file physically inside export_path() before serving it — closing both traversal and symlink escape routes (rconfig PR #349, rconfig Commit).
Successful exploitation allows any authenticated user to read arbitrary files on the server that are accessible to the web server process, with no impact on integrity or availability. High-value targets include the application's .env file (containing APP_KEY, DB_PASSWORD, database credentials, and mail configuration), Laravel log files, and other sensitive configuration files. Exposure of database credentials or encryption keys could enable further attacks such as database compromise, decryption of stored secrets, or lateral movement within the network infrastructure managed by rConfig (Github Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, as valid credentials are required. The EPSS score is approximately 0.37%, placing it in the 30th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/download-export route, which maps to FileDownloadController::download_export().filename parameter, e.g.:GET /download-export?filename=../../../../.env&type=exportor using URL encoding to bypass naive filters:GET /download-export?filename=..%2F..%2F..%2F..%2F.envexport_path() and, if the file exists, serves it directly. The attacker receives the contents of the .env file, exposing APP_KEY, DB_PASSWORD, and other secrets.APP_KEY to decrypt encrypted values stored by the Laravel application, enabling further compromise of the managed network infrastructure (rconfig PR #349, Github Advisory)./download-export with filename parameters containing ../, ..%2F, ....//, or absolute paths (e.g., /etc/passwd); requests where the filename parameter does not match a simple basename pattern (no path separators).activityLogIt) showing FILE DOWNLOAD warnings for filenames containing traversal sequences; web server access logs with requests to /download-export?filename= followed by encoded or literal ../ sequences..env, laravel.log, or /etc/passwd being served should be treated as a strong indicator.storage/logs/laravel.log) showing unexpected file access patterns or errors from FileDownloadController for paths outside the export directory.Upgrade rConfig to version 8.2.13 or later, which resolves the vulnerability by sanitizing the filename parameter through basename() and validating the resolved path with realpath() against the export directory (rconfig Release). As a temporary workaround, restrict access to the /download-export endpoint at the web server or firewall level to trusted IP ranges, and ensure the web server process runs with the minimum necessary file system permissions (principle of least privilege). Additionally, configure the web server to prevent direct serving of .env and storage paths, and set APP_DEBUG=false in production as recommended in the rConfig security documentation (rconfig Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."