Remote Code Execution Risk in Ansible Automation Controller by Red Hat
CVE-2026-71464

3.1LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-71464?

The vulnerability in Ansible Automation Controller stems from a missing validation check in the LaunchConfigurationBaseSerializer's scm_branch field. Unlike other serializers, this gap allows the acceptance of potentially harmful input, leading to a security risk of remote code execution. Although a runtime guard prevents immediate exploitation, the lack of API validation creates a significant security concern. This issue emphasizes the need for robust validation checks to prevent unauthorized command execution via malicious scm_branch inputs.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Chris Meyers (Red Hat).
.