6.6

CVE-2026-84716

Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames

A flaw was found in the automation-controller instance
                  install-bundle endpoint. When a System Administrator downloads
                  an execution/hop node's install bundle, the controller signs an
                  X.509 certificate with the receptor mesh certificate authority
                  in which the Common Name, DNS subject-alternative-name, and
                  receptor node-id are taken verbatim from the caller-chosen
                  instance hostname, with a hard-coded ten-year validity, a random
                  serial, and no issuance log or revocation list. Because the
                  hostname charset validator is case-insensitive while the
                  uniqueness validator is case-sensitive, an administrator can
                  register a case variant of an existing control node's hostname
                  and obtain a mesh-CA-signed certificate that TLS peers, which
                  match hostnames case-insensitively, accept as that control node.
                  In managed/hosted deployments — where the customer holds
                  controller superuser but the platform operator runs the mesh —
                  this yields a long-lived, non-revocable mesh peer credential and,
                  with an on-path position, TLS impersonation or interception of
                  control/hybrid mesh nodes. It does not grant direct remote code
                  execution, because receptor work submission is gated by a
                  separate signing key not included in the bundle.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 8
Default Statusaffected
Version 0:4.6.33-1.el8ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 9
Default Statusaffected
Version 0:4.6.33-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6 for RHEL 9
Default Statusaffected
Version 0:4.7.17-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version 1789673739
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version 1789580684
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.6 1.3 4.7
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://access.redhat.com/security/cve/CVE-2026-84716
https://bugzilla.redhat.com/show_bug.cgi?id=2527199
https://access.redhat.com/errata/RHSA-2026:71113
https://access.redhat.com/errata/RHSA-2026:71114
https://access.redhat.com/errata/RHSA-2026:71179
https://access.redhat.com/errata/RHSA-2026:71177