PT-2026-97544 · Red Hat · Automation-Controller
CVE-2026-84716
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
automation-controller (affected versions not specified)
Description
A flaw exists in the
install-bundle endpoint. When a System Administrator downloads an install bundle for an execution or hop node, the controller signs an X.509 certificate using the receptor mesh certificate authority. The Common Name, DNS subject-alternative-name, and receptor node-id are taken directly from the instance hostname chosen by the caller. These certificates have a hard-coded ten-year validity, random serials, and lack issuance logs or revocation lists.Due to a discrepancy where the hostname charset validator is case-insensitive but the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname. This allows them to obtain a signed certificate that TLS peers, which match hostnames case-insensitively, will accept as the legitimate control node. In managed or hosted deployments, this can lead to the creation of long-lived, non-revocable mesh peer credentials, enabling TLS impersonation or interception of control and hybrid mesh nodes if the attacker is in an on-path position.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Automation-Controller