PT-2026-97549 · Red Hat · Ansible Automation Platform Automation-Controller
CVE-2026-84721
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible Automation Platform automation-controller (affected versions not specified)
Description
A server-side request forgery flaw exists in the email notification backend. The system passes the user-supplied SMTP host and port from a notification template to the SMTP client without validating if the target is an internal, loopback, link-local, or reserved address. An authenticated user with organization notification-admin permissions can create or modify a template to point to an arbitrary internal address and trigger a test, causing the controller task process to open a raw TCP connection. This allows for a three-state internal port-scan oracle (open, closed, filtered) across the control-plane cluster network, including the in-cluster Kubernetes API. Additionally, if a shared organization template contains a stored SMTP password, redirecting the host may result in the transmission of that credential to an attacker-controlled server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller