{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apagerdutyrundeck/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92763"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rundeck (\u003c= 6.2.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PagerDuty"],"content_html":"\u003cp\u003eRundeck versions 6.2.1 and earlier are vulnerable to an authorization bypass flaw (CVE-2026-92763) within the project archive import functionality. The vulnerability specifically affects the handling of the 'importConfig' and 'importNodesSources' parameters. An attacker holding only basic 'import' permissions - which are intended for managing project archives - can leverage these parameters to manipulate sensitive configuration files. By exploiting this flaw, an attacker can modify security-critical settings such as node executor definitions and SSH key paths. This manipulation allows for the redirection of job execution, potentially enabling the attacker to execute arbitrary code or commands in the context of the Rundeck service or target managed nodes. This flaw is particularly significant as it effectively escalates the privileges of an import-authorized user to those of a project administrator.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a user with restricted import permissions to reconfigure project settings, leading to unauthorized code execution, credential exfiltration via modified SSH key paths, or full takeover of project-level automation tasks. This vulnerability affects all environments running Rundeck version 6.2.1 or older that utilize the project archive feature.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Rundeck to a patched version beyond 6.2.1 immediately to remediate CVE-2026-92763.\u003c/li\u003e\n\u003cli\u003eAudit the access control policies to identify and restrict users assigned the 'import' permission until the patch is applied.\u003c/li\u003e\n\u003cli\u003eReview Rundeck project configuration history and audit logs for unexpected modifications to 'project.properties' or node source configurations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:55:34Z","date_published":"2026-09-16T21:55:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rundeck-auth-bypass/","summary":"Rundeck versions through 6.2.1 contain an authorization vulnerability in the project archive import endpoint allowing low-privileged users to overwrite sensitive project configuration files.","title":"Authorization Bypass in Rundeck Project Archive Import","url":"https://feed.craftedsignal.io/briefs/2026-09-rundeck-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}