CVE-2026-84719
Received Received - Intake

Privilege Escalation in Ansible Automation Platform

Vulnerability report for CVE-2026-84719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: redhat-SADP

Description

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use β€” including the control-plane instance group β€” bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
redhat ansible_automation_platform *
red_hat ansible_automation_platform 2.4
red_hat ansible_automation_platform 2.5
red_hat ansible_automation_platform 2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ansible Automation Platform's automation-controller allows a user with organization workflow-admin permission to copy a WorkflowJobTemplate and gain administrator rights over it. The deep-copy sanitizer fails to validate permissions for instance_groups, execution_environment, and labels, enabling the user to bypass InstanceGroup use_role restrictions. This allows launching jobs on unauthorized instance groups, including the control-plane group, potentially running attacker-influenced automation in the control-plane execution context.

Impact Analysis

An attacker with workflow-admin permission could escalate privileges, run unauthorized jobs on restricted instance groups, and execute malicious automation in the control-plane context. This could lead to data breaches, unauthorized system access, or disruption of critical automation workflows, especially if the control-plane is compromised.

Compliance Impact

This vulnerability could lead to unauthorized access and execution of automation in the control-plane, potentially violating data confidentiality and integrity requirements in GDPR and HIPAA. Unauthorized job execution may result in data exposure or tampering, leading to compliance violations and regulatory penalties.

Mitigation Strategies

Update to the latest patched versions of Red Hat Ansible Automation Platform 2.4, 2.5, or 2.6 depending on your RHEL release. Apply the relevant RHSA updates: RHSA-2026:71115 for version 2.4, RHSA-2026:71114 for version 2.5, or RHSA-2026:71113 for version 2.6.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart