9.9
CVE-2026-84719
- EPSS 0.43%
- Veröffentlicht 23.09.2026 19:40:07
- Zuletzt bearbeitet 25.09.2026 19:17:58
- Erkennungen
Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.4 for RHEL 8
Default Statusaffected
Version
0:4.5.36-1.el8ap
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.4 for RHEL 9
Default Statusaffected
Version
0:4.5.36-1.el9ap
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.5 for RHEL 8
Default Statusaffected
Version
0:4.6.33-1.el8ap
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.5 for RHEL 9
Default Statusaffected
Version
0:4.6.33-1.el9ap
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Default Statusaffected
Version
0:4.7.17-1.el9ap
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version
1789673739
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version
1789580684
Version <
*
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.344 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://access.redhat.com/security/cve/CVE-2026-84719
https://bugzilla.redhat.com/show_bug.cgi?id=2527213
https://access.redhat.com/errata/RHSA-2026:71113
https://access.redhat.com/errata/RHSA-2026:71115
https://access.redhat.com/errata/RHSA-2026:71114
https://access.redhat.com/errata/RHSA-2026:71179
https://access.redhat.com/errata/RHSA-2026:71177