---
id: CVE-2026-106056
title: >-
  Rundeck before 6.2.0 contains an OS command injection vulnerability that
  allows authenticated users with job run permission to execute commands on
  Windows nodes by supplying crafted option values
summary: >-
  Rundeck before 6.2.0 contains an OS command injection vulnerability that
  allows authenticated users with job run permission to execute commands on
  Windows nodes by supplying crafted option values. Attackers can inject cmd.exe
  metacharact…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: rundeck
product: rundeck
affected:
  - rundeck < 6.2.0
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T12:17:08.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106056'
references:
  - url: 'https://github.com/rundeck/rundeck'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/cli/CLIUtils.java#L146-L158
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/commit/807d9cf0eef63669b342e02e05a740e97f84f013
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/pull/10414'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/releases/tag/v6.2.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rundeck-before-6.2.0-os-command-injection-via-windows-job-option-quoting
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T12:29:01.367Z'
---

## Overview

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
