CVE-2026-106056: fallo de gravedad alta en rundeck
Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.7
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
rundeck · rundeckCVEs relacionadas — rundeck
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-39132HIGHYAML deserialization can run untrusted codeEPSS 1.7%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2022-29186CRITICALUse of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterpriseEPSS 1.2%CVE-2021-41112HIGHMissing Authorization in RundeckEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%
Referencias
https://github.com/rundeck/rundeckhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/cli/CLIUtils.java#L146-L158https://github.com/rundeck/rundeck/commit/807d9cf0eef63669b342e02e05a740e97f84f013https://github.com/rundeck/rundeck/pull/10414https://github.com/rundeck/rundeck/releases/tag/v6.2.0https://www.vulncheck.com/advisories/rundeck-before-6.2.0-os-command-injection-via-windows-job-option-quoting