PT-2026-97544 · Red Hat · Automation-Controller

CVE-2026-84716

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions automation-controller (affected versions not specified)
Description A flaw exists in the install-bundle endpoint. When a System Administrator downloads an install bundle for an execution or hop node, the controller signs an X.509 certificate using the receptor mesh certificate authority. The Common Name, DNS subject-alternative-name, and receptor node-id are taken directly from the instance hostname chosen by the caller. These certificates have a hard-coded ten-year validity, random serials, and lack issuance logs or revocation lists.
Due to a discrepancy where the hostname charset validator is case-insensitive but the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname. This allows them to obtain a signed certificate that TLS peers, which match hostnames case-insensitively, will accept as the legitimate control node. In managed or hosted deployments, this can lead to the creation of long-lived, non-revocable mesh peer credentials, enabling TLS impersonation or interception of control and hybrid mesh nodes if the attacker is in an on-path position.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84716
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Automation-Controller