PT-2026-76571 · Ansible · Ansible
CVE-2026-55074
·
Published
2026-08-12
·
Updated
2026-08-19
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ansible versions prior to 2.0.0
Description
The jailexec connection plugin contains a flaw in the
put file function where transfer destinations are resolved to paths on the jail host. Because the plugin executes mkdir -p and mv as root on the host and follows symbolic links, an attacker who can create a symlink within the jail can trigger an arbitrary root-owned write on the host. This allows for a full jail escape, which can be escalated to complete host compromise by modifying files such as cron, rc.d, or authorized keys. This occurs when an operator runs a copy, template, or fetch-style task using put file and the attacker places a symlink at or above the destination path before the transfer.Recommendations
Update to version 2.0.0.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible