---
id: CVE-2026-92763
title: >-
  Rundeck through 6.2.1 fails to properly authorize the importConfig and
  importNodesSources parameters in the project archive import endpoint
summary: >-
  Rundeck through 6.2.1 fails to properly authorize the importConfig and
  importNodesSources parameters in the project archive import endpoint.
  Attackers with only the import action can replace project configuration files
  including security…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: rundeck
product: rundeck
affected:
  - rundeck <= 6.2.1
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:47:31.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92763'
references:
  - url: 'https://github.com/rundeck/rundeck'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rundeck/rundeck/blob/v5.20.1/rundeckapp/grails-app/controllers/rundeck/controllers/ProjectController.groovy#L3395-L3506
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/issues/10459'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rundeck-through-6.2.1-authorization-bypass-via-project-import
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rundeck/rundeck/issues/10459'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00509
epssPercentile: 0.40949
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T13:56:48.435753Z'
ingestedAt: '2026-09-16T21:05:36.895Z'
---

## Overview

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
