CVE-2026-105157
Received Received - Intake

Path Traversal in RainyGao DocSys

Vulnerability report for CVE-2026-105157, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rainygao docsys to 2.02.85 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in RainyGao DocSys up to version 2.02.85. It exists in the DocController.doGetTmp function of the file /Doc/doGetTmpFile.do. The flaw allows authenticated users to read arbitrary files on the server by manipulating the path and fileName parameters. The system fails to validate these inputs, enabling directory traversal sequences like ../ to escape the intended temporary download directory.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to /Doc/doGetTmpFile.do with path traversal sequences like ../ in the path or fileName parameters. Check Tomcat access logs for unusual file access patterns or attempts to read sensitive files such as /etc/passwd. Use tools like curl to test the endpoint with crafted inputs: curl 'http://target/Doc/doGetTmpFile.do?path=../&fileName=passwd'.

Impact Analysis

An attacker could exploit this to read sensitive files on the server, such as configuration files, user data, or system files like /etc/passwd. This could lead to unauthorized data access, information disclosure, or further attacks if credentials or keys are exposed. The impact depends on the server's file permissions and the files accessible by the Tomcat process.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) or HIPAA (health information privacy) by allowing unauthorized access to sensitive data. Organizations using DocSys may face legal penalties, reputational damage, or loss of certification if this flaw leads to data breaches or non-compliance with data protection regulations.

Mitigation Strategies

Immediately restrict access to the /Doc/doGetTmpFile.do endpoint by updating firewall rules or disabling the endpoint if not essential. Apply input validation to sanitize path and fileName parameters, ensuring they stay within intended directories. Canonicalize paths before file operations to prevent traversal sequences. Monitor for exploitation attempts and update to a patched version once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105157. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart