Skip to content
Threat Feed
high advisory

OS Command Injection in Rundeck via CLIUtils

Authenticated users can execute arbitrary OS commands on Windows nodes in Rundeck versions prior to 6.2.0 by injecting shell metacharacters into job options.

CVE search metadata

CVE search record: CVE-2026-106056. Severity: high. CVSS: 7.5. KEV: no. Product: Rundeck (< 6.2.0). Brief: OS Command Injection in Rundeck via CLIUtils. Brief link: https://feed.craftedsignal.io/briefs/2026-10-rundeck-rce/

Rundeck versions prior to 6.2.0 are vulnerable to an OS command injection flaw (CVE-2026-106056) affecting the CLIUtils.quoteWindowsCMDArg utility. This vulnerability allows an authenticated user who possesses job execution permissions to manipulate command-line arguments during job execution on Windows-based nodes. By providing crafted input within free-text job options containing shell metacharacters such as ampersands (&&) or pipes (|), an attacker can bypass the intended quoting mechanism. Because the utility wraps inputs in single quotes that are ineffective against these specific Windows shell metacharacters, the injected commands are executed by the node executor with its associated privileges. This flaw represents a significant risk for environments where internal users have access to job orchestration but are not intended to have full command-line access to the underlying infrastructure nodes.

Impact

Successful exploitation allows authenticated users to achieve arbitrary command execution on target Windows nodes. This can lead to full compromise of the affected nodes, privilege escalation within the context of the node executor, and potential lateral movement across the infrastructure managed by the compromised Rundeck instance. The scope of impact is limited to environments utilizing Rundeck to manage Windows-based systems where job options are not strictly validated.

Recommendation

  1. Upgrade Rundeck to version 6.2.0 or later immediately to resolve the vulnerability in CLIUtils.quoteWindowsCMDArg.
  2. Implement strict input validation for all free-text job options within Rundeck configurations to ensure they do not contain shell metacharacters.
  3. Review the principle of least privilege for accounts assigned job run permissions in Rundeck to minimize the impact of potential command injection attempts.
  4. Monitor process execution logs on Windows nodes managed by Rundeck for suspicious child processes spawned by the node executor account.

Immediate actions

Upgrade Rundeck to 6.2.0 or later

IT Operations 24h

Mitigations

Upgrade Rundeck to 6.2.0

immediate IT Operations

CVE-2026-106056