The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
SOONSTARTING SOONMicrosoft Windows & Surface EventIN 24MOpen coverage →
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Verified against the NVD record for CVE-2026-106056 (VulnCheck CNA, published 2026-10-07 12:17 UTC) and the CVE.org record (PUBLISHED 2026-10-07 11:59 UTC): product Rundeck, versions before 6.2.0, OS command injection on Windows nodes via CLIUtils.quoteWindowsCMDArg, CWE-78, CVSS 3.1 7.5 HIGH, fix 6.2.0, commit 807d9cf and PR #10414. Earlier hold was a false positive: web search had not indexed the new record.

Sourcing
1source

via NVD

NVD · track record
40Stories
100%Verified
2130d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Rundeck before 6.2.0 carries 7.5 CVSS command injection flaw
VERIFIEDBy Xavier Rivera· ·1 min read

Rundeck before 6.2.0 carries 7.5 CVSS command injection flaw

Rundeck before 6.2.0 contains an OS command injection vulnerability rated 7.5 HIGH that lets authenticated users run arbitrary commands on Windows nodes. The flaw was fixed in the 6.2.0 release.

Source:NVD
Post
Rundeck before 6.2.0 carries 7.5 CVSS command injection flaw
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Rundeck versions before 6.2.0 contain an OS command injection flaw rated 7.5 CVSS under CVE-2026-106056. Authenticated users on Windows nodes can exploit it by supplying crafted options that bypass quoting in CLIUtils.quoteWindowsCMDArg, allowing command execution with node credentials; version 6.2.0 resolves the issue.

Rundeck versions before 6.2.0 contain a high-severity OS command injection vulnerability tracked as CVE-2026-106056. VulnCheck, the assigning CNA, rates it 7.5 (HIGH) under CVSS 3.1 and classifies it as CWE-78, OS command injection.
An attacker with job run permission can supply crafted option values that inject cmd.exe metacharacters such as && or | into free-text options.
The flaw affects authenticated users on Windows nodes. An attacker with job run permission can supply crafted option values that inject cmd.exe metacharacters such as && or | into free-text options. The vulnerable method CLIUtils.quoteWindowsCMDArg wraps these inputs in single quotes that fail to neutralize the characters.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Execution occurs with the privileges of the node executor credentials.
Successful exploitation can result in high confidentiality, integrity, and availability consequences on affected nodes.
Fix released in version 6.2.0. The project addressed the quoting logic in commit 807d9cf0eef63669b342e02e05a740e97f84f013 and pull request 10414. The v6.2.0 release tag marks the corrected build.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Impact limited to Windows job execution. The 7.5 CVSS 3.1 score reflects an attack that requires network access, high attack complexity, low privileges, and no user interaction. Successful exploitation can result in high confidentiality, integrity, and availability consequences on affected nodes.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityrundeck
More fromNVD
  • IBM Langflow OSS flaw CVE-2026-104335 lets logged-in attackers run code

    Tech · 15h
  • NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin

    Tech · 4d
  • Critical CVE-2026-94541 in WPMobile.App Plugin

    Tech · 5d
More inTech
  • Rockstar: GTA 6 Players Can Rob Almost Any Location

    Tech · 1h
  • IGN Releases Full Verbatim GTA 6 Interview Transcript

    Tech · 1h
  • Google DeepMind and Meta back Biohub virtual cell with $300M

    Tech · 1h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    IBM Langflow OSS flaw CVE-2026-104335 lets logged-in attackers run code

    CVE-2026-104335 lets an authenticated remote attacker run arbitrary code on IBM Langflow OSS 1.0.0 through 1.12.2 because of improper access control. IBM rates it 8.8 (high) and says to upgrade to 1.12.3.

  • Tech· 

    NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin

    NVD has published CVE-2014-125130 on a CVSS 7.5 unauthenticated file read issue in the CodeArt Google MP3 Audio Player WordPress plugin through version 1.0.11. Remote attackers can reach wp-config.php and further sensitive files to enable site compromise, with exploitation first noted in 2023.

  • Tech· 

    Critical CVE-2026-94541 in WPMobile.App Plugin

    The WPMobile.App WordPress plugin is vulnerable to authorization bypass through version 11.82, enabling unauthenticated attackers to steal password-reset URLs when the mail-to-push feature is enabled. The flaw carries a CVSS score of 9.8 and can result in full account takeover for arbitrary users including administrators.

  • Tech· 

    JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4

    The JetFormBuilder WordPress plugin harbors a stored XSS issue through version 3.6.5.4 that permits unauthenticated script injection into post meta, which then executes via Select Field options.

  • Tech· 

    Ninja Forms File Uploads plugin vulnerable to CVSS 8.1 arbitrary file flaw

    Versions of the Ninja Forms - File Uploads plugin through 3.3.34 allow unauthenticated attackers to perform arbitrary file read, write, and deletion by abusing the Amazon S3 upload mechanism, with remote code execution possible when that feature is active.