7.7
CVE-2026-106056
- EPSS 1.22%
- Veröffentlicht 07.10.2026 11:59:36
- Zuletzt bearbeitet 07.10.2026 17:16:47
- Erkennungen
Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerrundeck
≫
Produkt
rundeck
Default Statusunaffected
Version
0
Version <
6.2.0
Status
affected
Version
6.2.0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.22% | 0.677 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://github.com/rundeck/rundeck
https://github.com/rundeck/rundeck/releases/tag/v6.2.0
https://github.com/rundeck/rundeck/pull/10414
https://github.com/rundeck/rundeck/commit/807d9cf0eef63669b342e02e05a740e97f84f013
https://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/cli/CLIUtils.java#L146-L158
https://www.vulncheck.com/advisories/rundeck-before-6.2.0-os-command-injection-via-windows-job-option-quoting