<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apagerdutyrundeck/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:55:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apagerdutyrundeck/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Rundeck Project Archive Import</title><link>https://feed.craftedsignal.io/briefs/2026-09-rundeck-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 21:55:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rundeck-auth-bypass/</guid><description>Rundeck versions through 6.2.1 contain an authorization vulnerability in the project archive import endpoint allowing low-privileged users to overwrite sensitive project configuration files.</description><content:encoded><![CDATA[<p>Rundeck versions 6.2.1 and earlier are vulnerable to an authorization bypass flaw (CVE-2026-92763) within the project archive import functionality. The vulnerability specifically affects the handling of the 'importConfig' and 'importNodesSources' parameters. An attacker holding only basic 'import' permissions - which are intended for managing project archives - can leverage these parameters to manipulate sensitive configuration files. By exploiting this flaw, an attacker can modify security-critical settings such as node executor definitions and SSH key paths. This manipulation allows for the redirection of job execution, potentially enabling the attacker to execute arbitrary code or commands in the context of the Rundeck service or target managed nodes. This flaw is particularly significant as it effectively escalates the privileges of an import-authorized user to those of a project administrator.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a user with restricted import permissions to reconfigure project settings, leading to unauthorized code execution, credential exfiltration via modified SSH key paths, or full takeover of project-level automation tasks. This vulnerability affects all environments running Rundeck version 6.2.1 or older that utilize the project archive feature.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Rundeck to a patched version beyond 6.2.1 immediately to remediate CVE-2026-92763.</li>
<li>Audit the access control policies to identify and restrict users assigned the 'import' permission until the patch is applied.</li>
<li>Review Rundeck project configuration history and audit logs for unexpected modifications to 'project.properties' or node source configurations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>