PT-2026-97508 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84486

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description Four debug views that trigger internal task, dependency, and workflow schedulers are accessible to any user, including unauthenticated clients, because their URL routing is not restricted by the debug setting in production builds. An unauthenticated remote attacker can repeatedly call these endpoints to acquire the cluster-wide scheduler advisory lock. Since the legitimate scheduler does not wait for this lock, real scheduler runs are skipped, which stalls job dispatch for all tenants and consumes controller web workers. Additionally, the debug root view discloses the list of available debug endpoints to unauthenticated callers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84486
RHSA-2026:71113

Affected Products

Ansible Automation Platform Automation-Controller