
Rundeck on Windows nodes has a quoting bug that turns a job option into a shell command. CVE-2026-106056: anyone with job run permission can slip && or | into a free-text option and run commands with the node's executor credentials. Fixed in 6.2.0. If that executor is a domain service account, that's a lot of reach. https://thecircuitry.to/article/rundeck-before-620-carries-75-cvss-command-injection-flaw-muy3i0ij
