PT-2026-97507 · Red Hat · Ansible Automation Platform Automation-Controller

·

CVE-2026-84474

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description A flaw exists where the host config key (provisioning-callback secret) is exposed to users with only the view jobtemplate read-level permission via the job template API and the activity stream. Additionally, when the controller is deployed behind the AAP gateway with an empty proxy allow-list, the provisioning callback endpoint trusts the client-supplied X-Forwarded-For header to identify the calling host. A minimally privileged or unauthenticated remote attacker can use the leaked secret and spoof the X-Forwarded-For header to match a host in the job template's inventory, allowing them to launch the job template against arbitrary managed hosts using the template's credentials. This leads to privilege escalation and remote code execution on the managed hosts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84474
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller