Vulnerability in Red Hat Ansible Automation Platform Automation-Controller
CVE-2026-84474

9.9CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-84474?

A security flaw exists in the Red Hat Ansible Automation Platform's automation-controller, where a provisioning-callback secret can be accessed by users with minimal permissions. This vulnerability arises from the exposure of the host_config_key in both the job template API representation and the activity stream. Additionally, due to trust in a client-supplied X-Forwarded-For header without proper validation in an empty proxy allow-list setup, a remote attacker with limited access may exploit this flaw. By obtaining the secret and spoofing the X-Forwarded-For header, an attacker can execute job templates against unauthorized managed hosts, potentially leading to privilege escalation and remote code execution.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Chris Meyers (Red Hat).
.