OS Command Injection Vulnerability in Rundeck by Chef Software
CVE-2026-106056

7.7HIGH

Key Information:

Vendor

Rundeck

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-106056?

Rundeck versions prior to 6.2.0 are susceptible to an OS command injection vulnerability. Authenticated users with job run permissions can exploit this weakness by injecting crafted metacharacters, such as '&&' or '|', into free-text job option fields. The vulnerability arises because the built-in CLIUtils.quoteWindowsCMDArg function provides inadequate sanitization, resulting in the execution of arbitrary commands with node executor credential privileges on Windows nodes, potentially compromising system integrity.

Affected Version(s)

rundeck 0 < 6.2.0

rundeck 6.2.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eldor Nabijonov
.