Vulnerability in Ansible Automation Platform's Automation-Controller Allows Unauthenticated Access
CVE-2026-84486

8.2HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-84486?

A significant flaw exists in the automation-controller of Red Hat Ansible Automation Platform, where four debug views improperly allow access to any user, including unauthenticated clients. This vulnerability permits an unauthenticated remote attacker to repeatedly trigger internal task, dependency, and workflow schedulers leading to the potential for job dispatch stalling for all tenants. Furthermore, the debug root view exposes the list of debug endpoints to unauthorized callers, increasing the risk of exploitation and resource depletion on the controller web workers.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.