<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Rundeck (&lt; 6.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/rundeck--6.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 12:37:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/rundeck--6.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in Rundeck via CLIUtils</title><link>https://feed.craftedsignal.io/briefs/2026-10-rundeck-rce/</link><pubDate>Wed, 07 Oct 2026 12:37:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-rundeck-rce/</guid><description>Authenticated users can execute arbitrary OS commands on Windows nodes in Rundeck versions prior to 6.2.0 by injecting shell metacharacters into job options.</description><content:encoded><![CDATA[<p>Rundeck versions prior to 6.2.0 are vulnerable to an OS command injection flaw (CVE-2026-106056) affecting the CLIUtils.quoteWindowsCMDArg utility. This vulnerability allows an authenticated user who possesses job execution permissions to manipulate command-line arguments during job execution on Windows-based nodes. By providing crafted input within free-text job options containing shell metacharacters such as ampersands (&amp;&amp;) or pipes (|), an attacker can bypass the intended quoting mechanism. Because the utility wraps inputs in single quotes that are ineffective against these specific Windows shell metacharacters, the injected commands are executed by the node executor with its associated privileges. This flaw represents a significant risk for environments where internal users have access to job orchestration but are not intended to have full command-line access to the underlying infrastructure nodes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users to achieve arbitrary command execution on target Windows nodes. This can lead to full compromise of the affected nodes, privilege escalation within the context of the node executor, and potential lateral movement across the infrastructure managed by the compromised Rundeck instance. The scope of impact is limited to environments utilizing Rundeck to manage Windows-based systems where job options are not strictly validated.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Rundeck to version 6.2.0 or later immediately to resolve the vulnerability in CLIUtils.quoteWindowsCMDArg.</li>
<li>Implement strict input validation for all free-text job options within Rundeck configurations to ensure they do not contain shell metacharacters.</li>
<li>Review the principle of least privilege for accounts assigned job run permissions in Rundeck to minimize the impact of potential command injection attempts.</li>
<li>Monitor process execution logs on Windows nodes managed by Rundeck for suspicious child processes spawned by the node executor account.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>command-injection</category><category>vulnerability</category></item></channel></rss>