7.1

CVE-2026-84714

Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment

A flaw was found in the automation-controller input-validation
                  guard sanitize_jinja(). The function uses two regular
                  expressions to reject user-supplied Jinja, but the patterns
                  stop at the first interior '}' or '%' character, so a Jinja
                  expression containing an inner brace (for example an empty
                  dict) is accepted while remaining valid Jinja. Because
                  sanitize_jinja() is the sole guard on several launch-time
                  fields — ad-hoc command module_args, Machine-credential
                  username / become_method / become_user, and inventory host
                  names — a low-privileged user can inject Jinja that ansible-core
                  evaluates in the execution environment. This enables execution
                  of arbitrary commands in the execution environment (bypassing an
                  administrator's AD_HOC_COMMANDS module allowlist) and disclosure
                  of secrets belonging to credentials the attacker cannot read
                  (by templating a co-attached credential's injected environment
                  variables), across the credential access-control boundary.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 8
Default Statusaffected
Version 0:4.6.33-1.el8ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 9
Default Statusaffected
Version 0:4.6.33-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6 for RHEL 9
Default Statusaffected
Version 0:4.7.17-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version 1789673739
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version 1789580684
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

https://access.redhat.com/security/cve/CVE-2026-84714
https://bugzilla.redhat.com/show_bug.cgi?id=2527198
https://access.redhat.com/errata/RHSA-2026:71113
https://access.redhat.com/errata/RHSA-2026:71114
https://access.redhat.com/errata/RHSA-2026:71179
https://access.redhat.com/errata/RHSA-2026:71177