CVE-2026-92763: Rundeck through 6.2.1 Authorization Bypass via Project Import
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rundeckto a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs only the Rundeck import action permission. They do not need broader project-configuration authorization to replace affected project configuration files through the project archive import endpoint.
What security-relevant settings can be changed?
The unauthorized import can replace project configuration files, including node executor settings and SSH key paths. These settings can affect how jobs are executed.
Are all Rundeck deployments affected by default?
The issue affects Rundeck through version 6.2.1 when a user has the import action and can use the project archive import endpoint. The provided information does not establish whether the required import permission is granted by default.
How can I determine whether a project may have been affected?
Review use of the project archive import endpoint by accounts that had only import action permissions, and inspect project configuration changes. Pay particular attention to changes in node executor configuration and SSH key paths.