{"api_version":"1","generated_at":"2026-09-23T21:50:22+00:00","cve":"CVE-2026-84724","urls":{"html":"https://cve.report/CVE-2026-84724","api":"https://cve.report/api/cve/CVE-2026-84724.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84724","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84724"},"summary":{"title":"Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process","description":"An argument-injection flaw was found in the Ansible Automation Platform automation-controller\nsystem-job subsystem. The system-job template launch endpoint stores a user-supplied \"days\"\nvariable without running the integer validation defined elsewhere for that field, and the\ndispatcher flattens the management-command argument list into a single string with spaces before\nthe job runner re-splits it, so spaces in the value become additional command-line arguments.\nBecause system jobs are executed in-process on the control node without the container isolation\napplied to all other job types, an authenticated user with superuser privileges can inject\narbitrary arguments — including Python's path option — into the control-plane awx-manage process,\ncontrolling its argument vector and the first entry of its module search path. Full remote code\nexecution requires an additional import gadget that is not present in the current management\ncommands, so the demonstrated impact is argument injection with control of the process search\npath rather than confirmed code execution.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-23 20:17:19","updated_at":"2026-09-23 20:17:19"},"problem_types":["CWE-88","CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527222","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2527222","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84724","name":"https://access.redhat.com/security/cve/CVE-2026-84724","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84724","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84724","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-02T01:56:06.322Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-23T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-26/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-27/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"automation-controller","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"}],"datePublic":"2026-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"An argument-injection flaw was found in the Ansible Automation Platform automation-controller\nsystem-job subsystem. The system-job template launch endpoint stores a user-supplied \"days\"\nvariable without running the integer validation defined elsewhere for that field, and the\ndispatcher flattens the management-command argument list into a single string with spaces before\nthe job runner re-splits it, so spaces in the value become additional command-line arguments.\nBecause system jobs are executed in-process on the control node without the container isolation\napplied to all other job types, an authenticated user with superuser privileges can inject\narbitrary arguments — including Python's path option — into the control-plane awx-manage process,\ncontrolling its argument vector and the first entry of its module search path. Full remote code\nexecution requires an additional import gadget that is not present in the current management\ncommands, so the demonstrated impact is argument injection with control of the process search\npath rather than confirmed code execution."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-88","description":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-23T19:40:42.159Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-84724"},{"name":"RHBZ#2527222","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527222"}],"timeline":[{"lang":"en","time":"2026-09-02T01:56:06.322Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-23T00:00:00.000Z","value":"Made public."}],"title":"Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-84724","datePublished":"2026-09-23T19:40:42.159Z","dateReserved":"2026-09-02T01:55:24.865Z","dateUpdated":"2026-09-23T19:40:42.159Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-23 20:17:19","lastModifiedDate":"2026-09-23 20:17:19","problem_types":["CWE-88","CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84724","Ordinal":"1","Title":"Automation-controller: automation-controller: systemjob extra_va","CVE":"CVE-2026-84724","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84724","Ordinal":"1","NoteData":"An argument-injection flaw was found in the Ansible Automation Platform automation-controller\nsystem-job subsystem. The system-job template launch endpoint stores a user-supplied \"days\"\nvariable without running the integer validation defined elsewhere for that field, and the\ndispatcher flattens the management-command argument list into a single string with spaces before\nthe job runner re-splits it, so spaces in the value become additional command-line arguments.\nBecause system jobs are executed in-process on the control node without the container isolation\napplied to all other job types, an authenticated user with superuser privileges can inject\narbitrary arguments — including Python's path option — into the control-plane awx-manage process,\ncontrolling its argument vector and the first entry of its module search path. Full remote code\nexecution requires an additional import gadget that is not present in the current management\ncommands, so the demonstrated impact is argument injection with control of the process search\npath rather than confirmed code execution.","Type":"Description","Title":"Automation-controller: automation-controller: systemjob extra_va"}]}}}