A diagram of Ansible Automation Platform’s main components | Image: Red Hat
TL;DR
Red Hat disclosed two critical security flaws in the Ansible Automation Platform. These Ansible Automation Platform vulnerabilities permit privilege escalation and unauthorized code execution. Administrators must apply the latest patches immediately to secure their environments.
- Product: Red Hat Ansible Automation Platform 2.4 for RHEL 8
- Vulnerabilities: 2 flaws (CVE-2026-75884, CVE-2026-84719)
- Highest severity: 9.9 (Critical · CVSSv3)
- Worst impact: Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 0:4.5.36-1.el8ap, 0:4.5.36-1.el9ap, 0:4.6.33-1.el8ap, 0:4.6.33-1.el9ap (+3) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-84719 | 9.9 | CWE-862 | 0:4.5.36-1.el8ap, 0:4.5.36-1.el9ap, 0:4.6.33-1.el8ap (+4) | Not exploited |
| CVE-2026-75884 | 9.1 | CWE-184 | 0:4.5.36-1.el8ap, 0:4.5.36-1.el9ap, 0:4.6.33-1.el8ap (+4) | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Sourced estimates indicate that thousands of enterprise organizations rely on Ansible to automate IT infrastructure. Therefore, security defects in this control plane create severe risks for corporate networks. The primary defect, CVE-2026-84719, carries a critical CVSS score of 9.9. A secondary flaw, CVE-2026-75884, holds a 9.1 rating. A successful breach enables attackers to extract namespace secrets or execute unauthorized code. Currently, no active exploitation in the wild or public proof-of-concept exploit code has been confirmed. However, delaying updates leaves critical automation controllers exposed to severe privilege escalation attacks.
How The Attack Works
The first flaw involves an incomplete input validation blocklist. An administrator exploits this weakness by injecting specific overrides into the container group configuration. Consequently, the attacker escalates privileges to gain OpenShift namespace-level access. This action allows the extraction of sensitive data, including admin passwords and database encryption keys.
The second vulnerability affects the automation-controller subsystem. When a user copies a workflow job template, the deep-copy permission sanitizer fails. The system omits authorization checks for instance groups preserved from the original workflow. As a result, a user can schedule automation jobs on restricted groups, including the control plane. This misconfiguration yields arbitrary code execution within the control-plane execution context.
Affected Versions
These critical Ansible Automation Platform vulnerabilities impact the AWX controller and the automation-controller subsystems. Deployments using standard cluster configurations face direct exposure. Containerized Podman installations remain unaffected by the container group override flaw.
Patch Or Mitigation Steps
System administrators must apply the latest Red Hat security updates. The vendor released patches that introduce strict authorization checks for deep-copy operations. Implementing these fixes eliminates the risk of privilege escalation.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!