{"api_version":"1","generated_at":"2026-09-23T21:50:22+00:00","cve":"CVE-2026-84718","urls":{"html":"https://cve.report/CVE-2026-84718","api":"https://cve.report/api/cve/CVE-2026-84718.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84718","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84718"},"summary":{"title":"Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust","description":"A flaw was found in the Ansible Automation Platform automation-controller. In the shipped\nproduction configuration, the Controller trusts the client-supplied X-Forwarded-For header as\nthe request's client IP without verifying that it originated from a trusted proxy, and selects\nthe leftmost (attacker-controlled) header value. As a result, an attacker can forge the source\nIP address recorded for their requests in the Controller's audit and access logs, degrading\nthe integrity of forensic and SIEM attribution. The flaw does not grant additional access.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-23 20:17:18","updated_at":"2026-09-23 20:17:18"},"problem_types":["CWE-348","CWE-348 Use of Less Trusted Source"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-84718","name":"https://access.redhat.com/security/cve/CVE-2026-84718","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527211","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2527211","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84718","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84718","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-02T01:18:40.552Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-23T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-26/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-27/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"automation-controller","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"}],"datePublic":"2026-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the Ansible Automation Platform automation-controller. In the shipped\nproduction configuration, the Controller trusts the client-supplied X-Forwarded-For header as\nthe request's client IP without verifying that it originated from a trusted proxy, and selects\nthe leftmost (attacker-controlled) header value. As a result, an attacker can forge the source\nIP address recorded for their requests in the Controller's audit and access logs, degrading\nthe integrity of forensic and SIEM attribution. The flaw does not grant additional access."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-348","description":"Use of Less Trusted Source","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-23T19:40:33.062Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-84718"},{"name":"RHBZ#2527211","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527211"}],"timeline":[{"lang":"en","time":"2026-09-02T01:18:40.552Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-23T00:00:00.000Z","value":"Made public."}],"title":"Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-348: Use of Less Trusted Source"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-84718","datePublished":"2026-09-23T19:40:33.062Z","dateReserved":"2026-09-02T01:18:24.873Z","dateUpdated":"2026-09-23T19:40:33.062Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-23 20:17:18","lastModifiedDate":"2026-09-23 20:17:18","problem_types":["CWE-348","CWE-348 Use of Less Trusted Source"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84718","Ordinal":"1","Title":"Automation-controller: automation-controller: client ip spoofing","CVE":"CVE-2026-84718","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84718","Ordinal":"1","NoteData":"A flaw was found in the Ansible Automation Platform automation-controller. In the shipped\nproduction configuration, the Controller trusts the client-supplied X-Forwarded-For header as\nthe request's client IP without verifying that it originated from a trusted proxy, and selects\nthe leftmost (attacker-controlled) header value. As a result, an attacker can forge the source\nIP address recorded for their requests in the Controller's audit and access logs, degrading\nthe integrity of forensic and SIEM attribution. The flaw does not grant additional access.","Type":"Description","Title":"Automation-controller: automation-controller: client ip spoofing"}]}}}