CVE-2026-92763 PUBLISHED

Rundeck through 6.2.1 Authorization Bypass via Project Import

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor rundeck
Product rundeck
Versions Default: unaffected
  • affected from 0 to 6.2.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Missing Authorization CWE