{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-106056", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-06T14:14:11.856Z", "datePublished": "2026-10-07T11:59:36.400Z", "dateUpdated": "2026-10-07T17:05:09.208Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-07T11:59:36.400Z" }, "datePublic": "2026-08-10T00:00:00.000Z", "title": "Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting", "descriptions": [ { "lang": "en", "value": "Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')", "cweId": "CWE-78", "type": "CWE" } ] } ], "affected": [ { "vendor": "rundeck", "product": "rundeck", "defaultStatus": "unaffected", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "6.2.0" }, { "version": "6.2.0", "status": "unaffected", "versionType": "semver" } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 7.7, "baseSeverity": "HIGH" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH" } } ], "references": [ { "url": "https://github.com/rundeck/rundeck/pull/10414", "tags": [ "patch", "issue-tracking" ], "name": "Pull Request #10414" }, { "url": "https://github.com/rundeck/rundeck/commit/807d9cf0eef63669b342e02e05a740e97f84f013", "tags": [ "patch" ], "name": "Patch Commit" }, { "url": "https://github.com/rundeck/rundeck", "tags": [ "product" ] }, { "url": "https://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/cli/CLIUtils.java#L146-L158", "tags": [ "technical-description" ] }, { "url": "https://github.com/rundeck/rundeck/releases/tag/v6.2.0", "tags": [ "release-notes" ], "name": "rundeck v6.2.0 Release Notes" }, { "name": "VulnCheck Advisory: Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/rundeck-before-6.2.0-os-command-injection-via-windows-job-option-quoting" } ], "credits": [ { "lang": "en", "value": "Eldor Nabijonov", "type": "finder" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T16:08:10.333316Z", "id": "CVE-2026-106056", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T17:05:09.208Z" } } ] } }