Authorization Bypass in Rundeck Affects Project Import Configuration
CVE-2026-92763

8.6HIGH

Key Information:

Vendor

Rundeck

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92763?

The Rundeck application prior to version 6.2.1 contains a security flaw where the importConfig and importNodesSources parameters are not properly authorized during the project archive import process. This design oversight permits attackers with minimal privileges, specifically those who possess the import action, to manipulate project configurations. Such actions can lead to alterations in critical security settings, including node executors and SSH key paths. Consequently, this vulnerability poses significant risks to job executions and overall system integrity.

Affected Version(s)

rundeck 0 <= 6.2.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.