Authorization Flaw in Ansible Automation Platform's AWX Impacting Bulk Job Launch API
CVE-2026-84470
6.4MEDIUM
What is CVE-2026-84470?
A flaw in the Ansible Automation Platform's automation-controller (AWX) allows users with only read-level access to instance groups to execute bulk job launches, compromising execution-placement isolation. The Bulk Job Launch API permits authorization based solely on read permissions, contrasting with the single-job launch process, which requires higher-level use permissions. This oversight enables unauthorized users, such as those in the System Auditor role, to initiate jobs on instance groups without proper authorization, potentially leading to unauthorized access and control over automation tasks.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Santosh Kumar Puppala (Independent security researcher) for reporting this issue.