Vulnerability in Red Hat Ansible Automation Platform Automation-Controller
CVE-2026-84474
What is CVE-2026-84474?
A security flaw exists in the Red Hat Ansible Automation Platform's automation-controller, where a provisioning-callback secret can be accessed by users with minimal permissions. This vulnerability arises from the exposure of the host_config_key in both the job template API representation and the activity stream. Additionally, due to trust in a client-supplied X-Forwarded-For header without proper validation in an empty proxy allow-list setup, a remote attacker with limited access may exploit this flaw. By obtaining the secret and spoofing the X-Forwarded-For header, an attacker can execute job templates against unauthorized managed hosts, potentially leading to privilege escalation and remote code execution.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved