CVE-2026-92763
largeMissing Authorization in Rundeck Project Archive Import Enables Config Tampering
Rundeck through 6.2.1 fails to enforce authorization on the importConfig and importNodesSources parameters of the project archive import endpoint, a missing-authorization flaw (CWE-862). An authenticated attacker who holds only the 'import' action on a project — without broader admin or configuration privileges — can invoke the import endpoint with those parameters enabled. This allows the attacker to replace project configuration files, including security-relevant settings such as node executors and SSH key paths that control how jobs execute, giving high integrity and confidentiality impact per the CVSS score. Any Rundeck deployment at version 6.2.1 or earlier in which less-privileged users are granted the import action is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known.
What to do: Upgrade Rundeck to a release newer than 6.2.1 as soon as a patched version is available. Until then, restrict the project 'import' action to trusted administrators, audit recent project archive import activity, and review project configuration files (node executors, SSH key paths) for unauthorized modifications.
| Rundeck (PagerDuty) Rundeck | all versions through 6.2.1 (<= 6.2.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.