OS Command Injection Vulnerability in Rundeck by Chef Software
CVE-2026-106056
7.7HIGH
What is CVE-2026-106056?
Rundeck versions prior to 6.2.0 are susceptible to an OS command injection vulnerability. Authenticated users with job run permissions can exploit this weakness by injecting crafted metacharacters, such as '&&' or '|', into free-text job option fields. The vulnerability arises because the built-in CLIUtils.quoteWindowsCMDArg function provides inadequate sanitization, resulting in the execution of arbitrary commands with node executor credential privileges on Windows nodes, potentially compromising system integrity.
Affected Version(s)
rundeck 0 < 6.2.0
rundeck 6.2.0
