PT-2026-97508 · Red Hat · Ansible Automation Platform Automation-Controller
CVE-2026-84486
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description
Four debug views that trigger internal task, dependency, and workflow schedulers are accessible to any user, including unauthenticated clients, because their URL routing is not restricted by the debug setting in production builds. An unauthenticated remote attacker can repeatedly call these endpoints to acquire the cluster-wide scheduler advisory lock. Since the legitimate scheduler does not wait for this lock, real scheduler runs are skipped, which stalls job dispatch for all tenants and consumes controller web workers. Additionally, the debug root view discloses the list of available debug endpoints to unauthenticated callers.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller