CVE-2026-87874
Awaiting Analysis Awaiting Analysis - Queue

Remote Code Execution in Ansible Community General Memcached Plugin

Vulnerability report for CVE-2026-87874, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: redhat-SADP

Description

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ansible memcached_cache_plugin *
community.general ansible to 2.11.0 (exc)
python-memcached python_memcached *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the memcached cache plugin of the community.general Ansible collection. The plugin stores data in memcached using python-memcached, which pickles values on write and unpickles them on read. Despite documentation claiming JSON storage, no explicit serialization is performed. An attacker can exploit this by injecting a crafted pickle payload into an unauthenticated, network-exposed memcached instance. When the Ansible controller reads the poisoned cache, the payload is deserialized and executed, leading to remote code execution.

Detection Guidance

Check for network-exposed memcached instances by scanning for port 11211. Inspect Ansible controller logs for unusual pickle deserialization events or unexpected code execution. Verify cache keys like 'ansible_facts<host>' for unexpected or large payloads.

Impact Analysis

If you use the memcached cache plugin in an insecure deployment where memcached is exposed and unauthenticated across a trust boundary, an attacker could gain remote code execution on your Ansible controller. This could allow them to take control of your Ansible environment, execute arbitrary commands, or access sensitive data. The impact depends on the privileges of the Ansible user and the network exposure of your memcached instance.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially compromising data confidentiality and integrity. For GDPR, this may result in unauthorized access to personal data, requiring breach notifications. For HIPAA, it could expose protected health information, violating compliance. The high CVSS score indicates significant impact on confidentiality, integrity, and availability, which are critical for compliance.

Mitigation Strategies

Bind memcached to localhost only, disable unauthenticated access across trust boundaries, and isolate the cache to the Ansible controller. Replace memcached with alternative cache plugins like redis, jsonfile, or yaml. Ensure only trusted hosts have write access to the fact-cache memcached.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87874. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart