PT-2026-97528 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84691

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description A flaw exists in the automation-controller where the log message formatting for API 4XX errors uses an administrator-controlled Python format-string template rendered with a live user object. Due to Python string formatting allowing attribute and item traversal, an authenticated administrator can craft a template to access application settings and retrieve the Django secret key and the database password. These secrets can be forwarded to an external log aggregator. This allows the administrator to obtain the master encryption key for stored credentials and the database service password, enabling offline decryption of credentials, user session forgery, and direct database access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84691
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller