Security Flaw in Ansible Runner Leading to Potential Unrestricted File Operations
CVE-2026-103754

5.9MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
1 October 2026

What is CVE-2026-103754?

A flaw in Ansible Runner allows for improper handling of zip archives during the extraction process. The unstream_dir() function fails to validate the targets of symbolic links extracted from the archive, enabling an attacker to create files and alter permissions in unintended directories. Specifically, this vulnerability can be exploited by crafting a malicious zip archive that influences the worker's input, resulting in unauthorized file creation or modification outside the designated directory. This security concern poses significant risks, including potential code execution on the affected systems.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Liqiang Ji (SQUARE Research Group, Institute of Software, Chinese Academy of Sciences (ISCAS)) for reporting this issue.
.