PT-2026-97543 · Red Hat · Automation-Controller+1
CVE-2026-84714
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
automation-controller (affected versions not specified)
Description
An input-validation flaw exists in the
sanitize jinja() function. The function employs two regular expressions to reject user-supplied Jinja, but these patterns stop at the first interior '}' or '%' character. Consequently, Jinja expressions containing inner braces, such as an empty dictionary, are accepted. Since sanitize jinja() is the only guard for several launch-time fields—including ad-hoc command module args, Machine-credential username, become method, become user, and inventory host names—a low-privileged user can inject Jinja that is evaluated by ansible-core in the execution environment. This allows for the execution of arbitrary commands, bypassing the AD HOC COMMANDS module allowlist, and the disclosure of secrets from credentials the attacker is not authorized to read by templating injected environment variables across the credential access-control boundary.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible-Core
Automation-Controller