Description
Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.
Published: 2026-10-07
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: OS Command Injection on Windows nodes
Action: Patch
AI Analysis

Impact

The issue allows an authenticated user with job run permission to inject metacharacters such as && or | into option values when executing a job targeting a Windows node. The injected text is passed to the underlying Windows command interpreter even though the CLIUtils.quoteWindowsCMDArg function wraps it in single quotes, resulting in arbitrary command execution. This represents a classic OS command injection flaw (CWE-78).

Affected Systems

Installations of Rundeck up to and including version 6.1.x are affected. The vulnerability resides in the CLIUtils component of the Rundeck core that processes job options for Windows nodes.

Risk and Exploitability

The CVSS score of 7.7 indicates a moderate to high potential impact if exploited. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. Attackers would need authenticated credentials with job run permissions; once privileged, they can execute arbitrary commands with the node executor's user context, potentially compromising the target Windows system.

Generated by OpenCVE AI on October 7, 2026 at 13:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rundeck to version 6.2.0 or later.
  • Revoke or limit job run permissions for untrusted users to reduce the attack surface.
  • Validate or restrict job option values to prevent injection of shell metacharacters.

Generated by OpenCVE AI on October 7, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.
Title Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T11:59:36.400Z

Reserved: 2026-10-06T14:14:11.856Z

Link: CVE-2026-106056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T12:17:08.520

Modified: 2026-10-07T12:17:08.520

Link: CVE-2026-106056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')