CVE-2026-85475
- EPSS 0.43%
- Veröffentlicht 23.09.2026 19:40:11
- Zuletzt bearbeitet 24.09.2026 15:17:46
A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATO...
CVE-2026-84719
- EPSS 0.43%
- Veröffentlicht 23.09.2026 19:40:07
- Zuletzt bearbeitet 25.09.2026 19:17:58
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to c...
CVE-2026-84714
- EPSS 0.29%
- Veröffentlicht 23.09.2026 19:40:06
- Zuletzt bearbeitet 24.09.2026 15:17:44
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first i...
CVE-2026-84706
- EPSS 0.31%
- Veröffentlicht 23.09.2026 19:39:57
- Zuletzt bearbeitet 26.09.2026 23:16:37
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-h...
CVE-2026-75884
- EPSS 0.41%
- Veröffentlicht 23.09.2026 19:39:52
- Zuletzt bearbeitet 24.09.2026 16:17:10
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account toke...
CVE-2026-84691
- EPSS 0.2%
- Veröffentlicht 23.09.2026 19:02:26
- Zuletzt bearbeitet 24.09.2026 14:51:56
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user objec...
CVE-2026-84683
- EPSS 0.26%
- Veröffentlicht 23.09.2026 19:02:18
- Zuletzt bearbeitet 25.09.2026 18:17:30
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequence...
CVE-2026-84499
- EPSS 0.38%
- Veröffentlicht 23.09.2026 18:47:54
- Zuletzt bearbeitet 26.09.2026 23:16:37
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalid...
CVE-2026-84502
- EPSS 0.62%
- Veröffentlicht 23.09.2026 18:47:26
- Zuletzt bearbeitet 24.09.2026 06:17:02
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls...
CVE-2026-84474
- EPSS 0.8%
- Veröffentlicht 23.09.2026 18:41:18
- Zuletzt bearbeitet 24.09.2026 06:17:01
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API represent...