CVE-2026-106056: falha de alta gravidade em rundeck
Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
Publicada em
18Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.7
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
rundeck · rundeckCVEs relacionadas — rundeck
No mesmo produto, das mais perigosas para as menos.
CVE-2021-39132HIGHYAML deserialization can run untrusted codeEPSS 1.7%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2022-29186CRITICALUse of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterpriseEPSS 1.2%CVE-2021-41112HIGHMissing Authorization in RundeckEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%
Referências
https://github.com/rundeck/rundeckhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/cli/CLIUtils.java#L146-L158https://github.com/rundeck/rundeck/commit/807d9cf0eef63669b342e02e05a740e97f84f013https://github.com/rundeck/rundeck/pull/10414https://github.com/rundeck/rundeck/releases/tag/v6.2.0https://www.vulncheck.com/advisories/rundeck-before-6.2.0-os-command-injection-via-windows-job-option-quoting