PT-2026-97550 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84724

·

Published

2026-09-23

·

Updated

2026-09-26

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform automation-controller (affected versions not specified)
Description An argument-injection flaw exists in the system-job subsystem. The system-job template launch endpoint fails to perform integer validation on the user-supplied days variable. The dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, allowing spaces within the value to be interpreted as additional command-line arguments. Since system jobs run in-process on the control node without container isolation, an authenticated user with superuser privileges can inject arbitrary arguments into the control-plane awx-manage process. This allows control over the argument vector and the first entry of the module search path. While full remote code execution would require an import gadget not currently present in management commands, the issue allows for argument injection and control of the process search path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84724
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller