CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106056

HIGHCVSS 7.5NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quot

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-106056 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106056

HIGHCVSS 7.5NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quot

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]