Client IP Spoofing Vulnerability in Ansible Automation Platform
CVE-2026-84718
4.3MEDIUM
What is CVE-2026-84718?
A vulnerability in the Ansible Automation Platform's automation-controller allows an attacker to manipulate the X-Forwarded-For header without proper validation from a trusted proxy. This flaw leads to the potential forgery of source IP addresses in the Controller's audit and access logs, thereby compromising the integrity of the logs. While it does not provide extra access to the attacker, the ability to alter recorded IP addresses undermines the reliability of legislative and forensic efforts in incident response.