{"api_version":"1","generated_at":"2026-09-23T21:49:45+00:00","cve":"CVE-2026-84486","urls":{"html":"https://cve.report/CVE-2026-84486","api":"https://cve.report/api/cve/CVE-2026-84486.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84486","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84486"},"summary":{"title":"Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos)","description":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Four debug views that trigger the internal task, dependency, and\nworkflow schedulers are configured to allow any user (including unauthenticated\nclients) and are routed in production builds because their URL include is not\ngated on the debug setting. An unauthenticated remote attacker can repeatedly\ninvoke these endpoints to acquire the cluster-wide scheduler advisory lock;\nbecause the legitimate scheduler acquires the same lock without waiting, the\nattacker causes real scheduler runs to be skipped, stalling job dispatch for\nall tenants, while also consuming controller web workers. The debug root view\nadditionally discloses the list of debug endpoints to unauthenticated callers.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-23 19:19:40","updated_at":"2026-09-23 20:17:17"},"problem_types":["CWE-489","CWE-489 Active Debug Code"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-84486","name":"https://access.redhat.com/security/cve/CVE-2026-84486","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527085","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2527085","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84486","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84486","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-01T20:42:20.853Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-23T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-84486","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-23T19:26:33.390389Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-23T19:41:49.501Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-26/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-27/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"automation-controller","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"}],"datePublic":"2026-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Four debug views that trigger the internal task, dependency, and\nworkflow schedulers are configured to allow any user (including unauthenticated\nclients) and are routed in production builds because their URL include is not\ngated on the debug setting. An unauthenticated remote attacker can repeatedly\ninvoke these endpoints to acquire the cluster-wide scheduler advisory lock;\nbecause the legitimate scheduler acquires the same lock without waiting, the\nattacker causes real scheduler runs to be skipped, stalling job dispatch for\nall tenants, while also consuming controller web workers. The debug root view\nadditionally discloses the list of debug endpoints to unauthenticated callers."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-489","description":"Active Debug Code","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-23T18:35:50.890Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-84486"},{"name":"RHBZ#2527085","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527085"}],"timeline":[{"lang":"en","time":"2026-09-01T20:42:20.853Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-23T00:00:00.000Z","value":"Made public."}],"title":"Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos)","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-489: Active Debug Code"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-84486","datePublished":"2026-09-23T18:35:50.890Z","dateReserved":"2026-09-01T20:41:23.322Z","dateUpdated":"2026-09-23T19:41:49.501Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-23 19:19:40","lastModifiedDate":"2026-09-23 20:17:17","problem_types":["CWE-489","CWE-489 Active Debug Code"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-23T19:26:33.390389Z","id":"CVE-2026-84486","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84486","Ordinal":"1","Title":"Automation-controller: automation-controller-container: automati","CVE":"CVE-2026-84486","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84486","Ordinal":"1","NoteData":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Four debug views that trigger the internal task, dependency, and\nworkflow schedulers are configured to allow any user (including unauthenticated\nclients) and are routed in production builds because their URL include is not\ngated on the debug setting. An unauthenticated remote attacker can repeatedly\ninvoke these endpoints to acquire the cluster-wide scheduler advisory lock;\nbecause the legitimate scheduler acquires the same lock without waiting, the\nattacker causes real scheduler runs to be skipped, stalling job dispatch for\nall tenants, while also consuming controller web workers. The debug root view\nadditionally discloses the list of debug endpoints to unauthenticated callers.","Type":"Description","Title":"Automation-controller: automation-controller-container: automati"}]}}}