PT-2026-76571 · Ansible · Ansible

CVE-2026-55074

·

Published

2026-08-12

·

Updated

2026-08-19

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 2.0.0
Description The jailexec connection plugin contains a flaw in the put file function where transfer destinations are resolved to paths on the jail host. Because the plugin executes mkdir -p and mv as root on the host and follows symbolic links, an attacker who can create a symlink within the jail can trigger an arbitrary root-owned write on the host. This allows for a full jail escape, which can be escalated to complete host compromise by modifying files such as cron, rc.d, or authorized keys. This occurs when an operator runs a copy, template, or fetch-style task using put file and the attacker places a symlink at or above the destination path before the transfer.
Recommendations Update to version 2.0.0.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55074
GHSA-CXGV-HP74-JJ7R
PYSEC-2026-3658

Affected Products

Ansible