PatchSiren

rundeck CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH rundeck CVE published 2026-10-07

CVE-2026-106056

CVE-2026-106056 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T11:59:36.400Z and has not been modified since then. This high-severity vulnerability in Rundeck before 6.2.0 allows authenticated users to inject OS commands on Windows nodes. The vulnerability exists due to ineffective quoting of Windows command-line arguments, enabling attackers to execute commands wi [truncated]