CVE-2026-106056 PUBLISHED

Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting

Assigner: VulnCheck
Reserved: 06.10.2026 Published: 07.10.2026 Updated: 07.10.2026

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor rundeck
Product rundeck
Versions Default: unaffected
  • affected from 0 to 6.2.0 (excl.)
  • Version 6.2.0 is unaffected

Credits

  • Eldor Nabijonov finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE