PT-2026-97543 · Red Hat · Automation-Controller+1

CVE-2026-84714

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions automation-controller (affected versions not specified)
Description An input-validation flaw exists in the sanitize jinja() function. The function employs two regular expressions to reject user-supplied Jinja, but these patterns stop at the first interior '}' or '%' character. Consequently, Jinja expressions containing inner braces, such as an empty dictionary, are accepted. Since sanitize jinja() is the only guard for several launch-time fields—including ad-hoc command module args, Machine-credential username, become method, become user, and inventory host names—a low-privileged user can inject Jinja that is evaluated by ansible-core in the execution environment. This allows for the execution of arbitrary commands, bypassing the AD HOC COMMANDS module allowlist, and the disclosure of secrets from credentials the attacker is not authorized to read by templating injected environment variables across the credential access-control boundary.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84714
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible-Core
Automation-Controller