CVE-2026-106056
Received Received - Intake

Rundeck OS Command Injection via Job Options

Vulnerability report for CVE-2026-106056, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rundeck rundeck 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Rundeck before version 6.2.0 has an OS command injection flaw where authenticated users with job run permissions can execute arbitrary commands on Windows nodes. The issue occurs because the CLIUtils.quoteWindowsCMDArg function incorrectly wraps inputs in single quotes, which cmd.exe does not handle properly. Attackers can inject metacharacters like && or | into free-text options to bypass restrictions and run commands with the node executor's privileges.

Detection Guidance

Check Rundeck versions before 6.2.0 for the vulnerability. Inspect job options for free-text inputs containing cmd.exe metacharacters like &&, ||, or |. Review CLIUtils.quoteWindowsCMDArg function usage in Windows node executions.

Impact Analysis

If exploited, this vulnerability allows attackers to execute arbitrary commands on Windows systems managed by Rundeck with the privileges of the node executor account. This could lead to unauthorized access, data theft, system manipulation, or further network compromise. The impact depends on the permissions of the node executor account.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements under GDPR (data protection), HIPAA (health information security), and other regulations. Organizations using affected Rundeck versions may face legal penalties, reputational damage, and increased audit scrutiny due to inadequate security controls.

Mitigation Strategies

Upgrade Rundeck to version 6.2.0 or later. Restrict job run permissions to trusted users. Audit existing jobs for suspicious option values. Monitor Windows nodes for unexpected command executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart