9.9

CVE-2026-84719

Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)

A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,
unified_job_template, and credentials of each cloned node and fails to check the instance_groups
(and execution_environment and labels) that were preserved from the original. A user with
organization workflow-admin permission but no role on the referenced instance groups can copy a
workflow, become its administrator, and launch jobs pinned to instance groups they are not
authorized to use — including the control-plane instance group — bypassing the InstanceGroup
use_role boundary and causing attacker-influenced automation to run in the control-plane
execution context.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.4 for RHEL 8
Default Statusaffected
Version 0:4.5.36-1.el8ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.4 for RHEL 9
Default Statusaffected
Version 0:4.5.36-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 8
Default Statusaffected
Version 0:4.6.33-1.el8ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 9
Default Statusaffected
Version 0:4.6.33-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6 for RHEL 9
Default Statusaffected
Version 0:4.7.17-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.6
Default Statusaffected
Version 1789673739
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version 1789580684
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.344
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://access.redhat.com/security/cve/CVE-2026-84719
https://bugzilla.redhat.com/show_bug.cgi?id=2527213
https://access.redhat.com/errata/RHSA-2026:71113
https://access.redhat.com/errata/RHSA-2026:71115
https://access.redhat.com/errata/RHSA-2026:71114
https://access.redhat.com/errata/RHSA-2026:71179
https://access.redhat.com/errata/RHSA-2026:71177