rundeck
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, rundeck recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, rundeck had the most security vulnerabilities in the rundeck ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-92763Rundeck through 6.2.1 Authorization Bypass via Project Import | Exploitation statusPublic exploit | FixYes | Affected productrundeck | Published09/16/2026 | SeverityHigh |
CVE-2023-47112Authenticated users can view job names and groups they do not have authorization to view in Rundeck | Exploitation statusNot known exploited | FixYes | Affected productrundeck | Published11/16/2023 | SeverityMedium |
CVE-2023-48222Authenticated users can view or delete jobs they do not have authorization for in Rundeck | Exploitation statusNot known exploited | FixNot confirmed | Affected productrundeck | Published11/16/2023 | SeverityHigh |
CVE-2022-31044Plaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process Automation | Exploitation statusNot known exploited | FixNot confirmed | Affected productrundeck | Published06/15/2022 | SeverityHigh |
CVE-2022-29186Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise | Exploitation statusNot known exploited | FixNot confirmed | Affected productrundeck | Published05/20/2022 | SeverityCritical |
CVE-2021-41112Missing Authorization in Rundeck | Exploitation statusNot known exploited | FixNot confirmed | Affected productrundeck | Published02/28/2022 | SeverityHigh |
CVE-2021-41111Authorization Bypass Through User-Controlled Key in Rundeck | Exploitation statusNot known exploited | FixNot confirmed | Affected productrundeck | Published02/28/2022 | SeverityMedium |
CVE-2021-39133Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server | Exploitation statusNot confirmed | FixNot confirmed | Affected productrundeck | Published08/30/2021 | SeverityHigh |
CVE-2021-39132YAML deserialization can run untrusted code | Exploitation statusNot confirmed | FixNot confirmed | Affected productrundeck | Published08/30/2021 | SeverityHigh |
CVE-2020-11009IDOR can reveal execution data and logs to unauthorized user in Rundeck | Exploitation statusNot confirmed | FixYes | Affected productrundeck | Published04/29/2020 | SeverityMedium |