CVE-2026-32981 Details
Description
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
A path traversal vulnerability exists in Ray Dashboard versions prior to 2.8.1, specifically on the default port 8265. The vulnerability arises from inadequate validation and sanitization of user-supplied file paths in the static file handling process. This flaw allows attackers to manipulate path traversal sequences, such as '../', to access files outside the designated static directory, resulting in unauthorized local file disclosure.
Users are advised to update Ray Dashboard to version 2.8.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:19712 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:24977 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:42644 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:5809 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:6761 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:6762 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-32981 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2448440 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32981.json | redhat-SADP | |
| https://github.com/ray-project/ray | [email protected] | Product |
| https://packetstorm.news/files/id/215801/ | [email protected] | ExploitThird Party Advisory |
| https://www.vulncheck.com/advisories/ray-dashboard-path-traversal-leading-to-local-file-disclosure | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | redhat-SADP |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| anyscale ray | < 2.8.1 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | redhat-SADP |
| Sep 2, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | New CVE Received | [email protected] |