Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
References
Configurations
No configuration.
History
17 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/rundeck/rundeck/issues/10459 - |
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 14:17
NVD link : CVE-2026-92763
Mitre link : CVE-2026-92763
CVE.ORG link : CVE-2026-92763
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
