Description
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Missing authorization allows attackers to alter project configuration files, potentially changing node executors and SSH key paths, leading to unauthorized job execution.
Action: Patch
AI Analysis

Impact

Rundeck through 6.2.1 fails to enforce authorization on the importConfig and importNodesSources parameters of the project archive import endpoint. An attacker who has only the ability to trigger an import can supply crafted values that replace critical configuration files, including node executors and SSH key paths, thereby subverting job execution security controls.

Affected Systems

Rundeck versions up to 6.2.1 are affected. It is unclear whether earlier major releases also use the same import mechanism; administrators should verify whether their deployed version falls within the vulnerable range.

Risk and Exploitability

The vulnerability receives a CVSS score of 8.6, indicating high severity, yet the EPSS score is below 1%, suggesting low likelihood of active exploitation at present. It is not listed in CISA KEV. Attackers would exploit the project archive import REST endpoint after authenticating and obtaining import privileges, using the unchecked importConfig and importNodesSources parameters.

Generated by OpenCVE AI on September 18, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Rundeck version that contains the fix (e.g., 6.2.2 or newer).
  • Restrict the ‘import’ permission to only trusted administrators or service accounts that absolutely need it.
  • Audit existing project configuration files for unexpected changes, focusing on node executor and SSH key path settings.
  • Monitor system logs for import operations and any anomalous configuration changes.

Generated by OpenCVE AI on September 18, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Rundeck
Rundeck rundeck
Vendors & Products Rundeck
Rundeck rundeck

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
Title Rundeck through 6.2.1 Authorization Bypass via Project Import
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:57:18.983Z

Reserved: 2026-09-16T19:06:21.229Z

Link: CVE-2026-92763

cve-icon Vulnrichment

Updated: 2026-09-17T13:57:12.946Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:25.150

Modified: 2026-09-24T20:47:31.797

Link: CVE-2026-92763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses