CVE-2026-89091
Received Received - Intake

Path Traversal in Ansible Galaxy Collection Installer

Vulnerability report for CVE-2026-89091, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat ansible-core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ansible-core allows an attacker to create a malicious collection that uses symbolic links to write files outside the intended directory when installed via ansible-galaxy. The flaw bypasses a previous fix by not resolving symlinks properly, enabling arbitrary file writes with the user's privileges.

Detection Guidance

This vulnerability involves malicious Ansible collections exploiting symlink handling during installation. To detect it, inspect installed collections for unexpected files or symlinks outside intended directories. Check ansible-galaxy logs for suspicious paths. No direct detection commands are provided in the context.

Impact Analysis

If you install a crafted collection, an attacker could overwrite critical system files or execute malicious code on your control node. This could lead to system compromise, data loss, or unauthorized access, depending on the files targeted.

Compliance Impact

This vulnerability could lead to unauthorized file access or modification, violating data integrity and confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations if sensitive data is exposed or altered due to the flaw.

Mitigation Strategies

Avoid installing untrusted collections. Update ansible-core to a patched version addressing this flaw. Review installed collections for suspicious files. Restrict write permissions to ansible directories. Monitor for unexpected file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart