Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match
Summary
| CVE | CVE-2026-84474 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-23 19:19:39 UTC |
| Updated | 2026-09-24 06:17:01 UTC |
| Description | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling host when the controller is deployed behind the AAP gateway with an empty proxy allow-list. By reading the secret and spoofing X-Forwarded-For to match any host in the job template's inventory, a minimally privileged or unauthenticated remote attacker can launch the job template against arbitrary managed hosts using the job template's credentials, resulting in privilege escalation and remote code execution on managed hosts. |
Risk And Classification
Primary CVSS: v3.1 9.9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.008010000 probability, percentile 0.546850000 (date 2026-09-24)
Problem Types: CWE-807 | CWE-807 Reliance on Untrusted Inputs in a Security Decision
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 8 | unaffected 0:4.5.36-1.el8ap * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 9 | unaffected 0:4.5.36-1.el9ap * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 8 | unaffected 0:4.6.33-1.el8ap * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 9 | unaffected 0:4.6.33-1.el9ap * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.6 For RHEL 9 | unaffected 0:4.7.17-1.el9ap * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.6 | unaffected 1789673739 * rpm | Not specified |
| CNA | Red Hat | Red Hat Ansible Automation Platform 2.7 | unaffected 1789580684 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:71113 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:71179 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:71177 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:71114 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-84474 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:71115 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This issue was discovered by Chris Meyers (Red Hat). (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-09-01T20:21:29.165Z | Reported to Red Hat. |
| CNA | 2026-09-23T00:00:00.000Z | Made public. |
Workarounds
CNA: - Restrict who holds view_jobtemplate on job templates that have provisioning callback enabled; disable provisioning callback (clear host_config_key) on JTs that do not require it. - Set PROXY_IP_ALLOWED_LIST to the AAP gateway/envoy address(es) so untrusted client X-Forwarded-For headers are stripped before host matching. - Rotate any host_config_key values that may have been exposed to read-only users; review activity_stream access. - Monitor for jobs with launch_type=callback and unexpected limit values or created_by=None.