ZeroHour

CVE-2026-92763

large

Missing Authorization in Rundeck Project Archive Import Enables Config Tampering

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Rundeck through 6.2.1 fails to enforce authorization on the importConfig and importNodesSources parameters of the project archive import endpoint, a missing-authorization flaw (CWE-862). An authenticated attacker who holds only the 'import' action on a project — without broader admin or configuration privileges — can invoke the import endpoint with those parameters enabled. This allows the attacker to replace project configuration files, including security-relevant settings such as node executors and SSH key paths that control how jobs execute, giving high integrity and confidentiality impact per the CVSS score. Any Rundeck deployment at version 6.2.1 or earlier in which less-privileged users are granted the import action is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known.

What to do: Upgrade Rundeck to a release newer than 6.2.1 as soon as a patched version is available. Until then, restrict the project 'import' action to trusted administrators, audit recent project archive import activity, and review project configuration files (node executors, SSH key paths) for unauthorized modifications.

Affected
Rundeck (PagerDuty) Rundeckall versions through 6.2.1 (<= 6.2.1)
Estimated exposure
largeplausibly tens of thousands of Rundeck deployments worldwide (thousands of internet-exposed instances, with many more internal enterprise installs) — Rundeck is a long-lived, widely adopted open-source runbook automation platform commonly deployed inside enterprises; public internet scans index thousands of exposed Rundeck servers, and total installations including internal deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.