Patch Commitpatch
https://github.com/rconfig/rconfig/commit/d133a466a2df9d065177de9a8ed50f1bfe438aee CVE-2026-64826
HIGH
rConfig < 8.2.13 Path Traversal File Read via FileDownloadController
Record summary
CVE-2026-64826 has a selected CVSS score of 7.1 (high).
Description
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
rConfigBrowse rConfig / rConfigDefault status: affected | CVE List | Before 8.2.13 | affected |
References
5Pull Requestissue tracking
https://github.com/rconfig/rconfig/pull/349 Release Notesrelease notes
https://github.com/rconfig/rconfig/releases/tag/core-8.2.13 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-64826 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/rconfig-path-traversal-file-read-via-filedownloadcontroller