{"api_version":"1","generated_at":"2026-09-11T03:26:16+00:00","cve":"CVE-2026-87874","urls":{"html":"https://cve.report/CVE-2026-87874","api":"https://cve.report/api/cve/CVE-2026-87874.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87874","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87874"},"summary":{"title":"Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller","description":"A flaw was found in the memcached cache plugin of the community.general Ansible\ncollection. Although its documentation states that records are stored in JSON\nformat, the plugin performs no explicit serialization and relies on\npython-memcached, which pickles values on write and unpickles them on read.\nBecause memcached is unauthenticated and cache keys are predictable, an attacker\nable to reach a network-exposed or shared memcached instance can write a crafted\npickle payload that is deserialized and executed on the Ansible controller when\nthe poisoned fact cache is next read, leading to remote code execution.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-09 17:17:53","updated_at":"2026-09-09 20:13:26"},"problem_types":["CWE-502","CWE-502 Deserialization of Untrusted Data"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-87874","name":"https://access.redhat.com/security/cve/CVE-2026-87874","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530995","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2530995","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87874","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87874","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ceph Storage 5","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ceph Storage 9","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenStack Platform 18.0","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-09T14:42:30.081Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-09T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Bind memcached to localhost only (the plugin default, 127.0.0.1:11211) and\n  never expose an unauthenticated memcached across a trust boundary; isolate the\n  cache to the controller. Prefer the redis cache plugin (explicit JSON) or the\n  jsonfile/yaml cache plugins where a shared/remote fact cache is required. Treat\n  any host with write access to the fact-cache memcached as trusted to run code\n  on the controller.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Red Hat would like to thank Jeong Woochang for reporting this issue.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-87874","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-09T16:58:33.648402Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-09T16:59:14.348Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ceph_storage:5"],"defaultStatus":"affected","packageName":"ansible-collection-community-general","product":"Red Hat Ceph Storage 5","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ceph_storage:9"],"defaultStatus":"affected","packageName":"ansible-collection-community-general","product":"Red Hat Ceph Storage 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openstack:17.1"],"defaultStatus":"affected","packageName":"ansible-collection-community-general","product":"Red Hat OpenStack Platform 17.1","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openstack:18.0"],"defaultStatus":"affected","packageName":"ansible-collection-community-general","product":"Red Hat OpenStack Platform 18.0","vendor":"Red Hat"}],"credits":[{"lang":"en","value":"Red Hat would like to thank Jeong Woochang for reporting this issue."}],"datePublic":"2026-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the memcached cache plugin of the community.general Ansible\ncollection. Although its documentation states that records are stored in JSON\nformat, the plugin performs no explicit serialization and relies on\npython-memcached, which pickles values on write and unpickles them on read.\nBecause memcached is unauthenticated and cache keys are predictable, an attacker\nable to reach a network-exposed or shared memcached instance can write a crafted\npickle payload that is deserialized and executed on the Ansible controller when\nthe poisoned fact cache is next read, leading to remote code execution."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-502","description":"Deserialization of Untrusted Data","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-09T16:06:22.995Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-87874"},{"name":"RHBZ#2530995","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530995"}],"timeline":[{"lang":"en","time":"2026-09-09T14:42:30.081Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-09T00:00:00.000Z","value":"Made public."}],"title":"Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller","workarounds":[{"lang":"en","value":"Bind memcached to localhost only (the plugin default, 127.0.0.1:11211) and\n  never expose an unauthenticated memcached across a trust boundary; isolate the\n  cache to the controller. Prefer the redis cache plugin (explicit JSON) or the\n  jsonfile/yaml cache plugins where a shared/remote fact cache is required. Treat\n  any host with write access to the fact-cache memcached as trusted to run code\n  on the controller."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-502: Deserialization of Untrusted Data"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-87874","datePublished":"2026-09-09T16:06:22.995Z","dateReserved":"2026-09-09T13:36:20.508Z","dateUpdated":"2026-09-09T16:59:14.348Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-09 17:17:53","lastModifiedDate":"2026-09-09 20:13:26","problem_types":["CWE-502","CWE-502 Deserialization of Untrusted Data"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-09T16:58:33.648402Z","id":"CVE-2026-87874","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87874","Ordinal":"1","Title":"Community.general: community.general: memcached cache plugin des","CVE":"CVE-2026-87874","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87874","Ordinal":"1","NoteData":"A flaw was found in the memcached cache plugin of the community.general Ansible\ncollection. Although its documentation states that records are stored in JSON\nformat, the plugin performs no explicit serialization and relies on\npython-memcached, which pickles values on write and unpickles them on read.\nBecause memcached is unauthenticated and cache keys are predictable, an attacker\nable to reach a network-exposed or shared memcached instance can write a crafted\npickle payload that is deserialized and executed on the Ansible controller when\nthe poisoned fact cache is next read, leading to remote code execution.","Type":"Description","Title":"Community.general: community.general: memcached cache plugin des"}]}}}