{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rundeck--6.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-106056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rundeck (\u003c 6.2.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["PagerDuty"],"content_html":"\u003cp\u003eRundeck versions prior to 6.2.0 are vulnerable to an OS command injection flaw (CVE-2026-106056) affecting the CLIUtils.quoteWindowsCMDArg utility. This vulnerability allows an authenticated user who possesses job execution permissions to manipulate command-line arguments during job execution on Windows-based nodes. By providing crafted input within free-text job options containing shell metacharacters such as ampersands (\u0026amp;\u0026amp;) or pipes (|), an attacker can bypass the intended quoting mechanism. Because the utility wraps inputs in single quotes that are ineffective against these specific Windows shell metacharacters, the injected commands are executed by the node executor with its associated privileges. This flaw represents a significant risk for environments where internal users have access to job orchestration but are not intended to have full command-line access to the underlying infrastructure nodes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to achieve arbitrary command execution on target Windows nodes. This can lead to full compromise of the affected nodes, privilege escalation within the context of the node executor, and potential lateral movement across the infrastructure managed by the compromised Rundeck instance. The scope of impact is limited to environments utilizing Rundeck to manage Windows-based systems where job options are not strictly validated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Rundeck to version 6.2.0 or later immediately to resolve the vulnerability in CLIUtils.quoteWindowsCMDArg.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for all free-text job options within Rundeck configurations to ensure they do not contain shell metacharacters.\u003c/li\u003e\n\u003cli\u003eReview the principle of least privilege for accounts assigned job run permissions in Rundeck to minimize the impact of potential command injection attempts.\u003c/li\u003e\n\u003cli\u003eMonitor process execution logs on Windows nodes managed by Rundeck for suspicious child processes spawned by the node executor account.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T12:37:14Z","date_published":"2026-10-07T12:37:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-rundeck-rce/","summary":"Authenticated users can execute arbitrary OS commands on Windows nodes in Rundeck versions prior to 6.2.0 by injecting shell metacharacters into job options.","title":"OS Command Injection in Rundeck via CLIUtils","url":"https://feed.craftedsignal.io/briefs/2026-10-rundeck-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Rundeck (\u003c 6.2.0)","version":"https://jsonfeed.org/version/1.1"}