PT-2026-97549 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84721

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform automation-controller (affected versions not specified)
Description A server-side request forgery flaw exists in the email notification backend. The system passes the user-supplied SMTP host and port from a notification template to the SMTP client without validating if the target is an internal, loopback, link-local, or reserved address. An authenticated user with organization notification-admin permissions can create or modify a template to point to an arbitrary internal address and trigger a test, causing the controller task process to open a raw TCP connection. This allows for a three-state internal port-scan oracle (open, closed, filtered) across the control-plane cluster network, including the in-cluster Kubernetes API. Additionally, if a shared organization template contains a stored SMTP password, redirecting the host may result in the transmission of that credential to an attacker-controlled server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84721

Affected Products

Ansible Automation Platform Automation-Controller