{"id":"CVE-2026-84474","title":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller","summary":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. The provisioning-callback secret (host_config_key) is exposed to\nusers holding only the read-level view_jobtemplate permission -- both in the\njob template …","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-807"],"vendor":"Red Hat","product":"automation-controller","affected":["automation-controller (all versions)","automation-controller (all versions)","automation-controller (all versions)","automation-controller (all versions)","automation-controller (all versions)","ansible-automation-platform-26/controller-rhel9 (all versions)","ansible-automation-platform-27/controller-rhel9 (all versions)"],"published":"2026-09-23","updated":"2026-09-24","sourceUpdated":"2026-09-24T06:17:01.990","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84474","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71115","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71177","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71179","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84474","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527073","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-84474.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84474"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84474"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T19:28:08.444949Z"},"ingestedAt":"2026-09-23T19:31:04.469Z","patched":["ansible_automation_platform_2_4_for_rhel 8","ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_4_for_rhel 9","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","ansible_automation_platform 2.6","ansible_automation_platform 2.7"],"slug":"CVE-2026-84474","body":"## Overview\n\nA flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. The provisioning-callback secret (host_config_key) is exposed to\nusers holding only the read-level view_jobtemplate permission -- both in the\njob template API representation and in the activity stream -- and the\nprovisioning callback endpoint trusts a client-supplied X-Forwarded-For\nheader to determine the calling host when the controller is deployed behind\nthe AAP gateway with an empty proxy allow-list. By reading the secret and\nspoofing X-Forwarded-For to match any host in the job template's inventory, a\nminimally privileged or unauthenticated remote attacker can launch the job\ntemplate against arbitrary managed hosts using the job template's credentials,\nresulting in privilege escalation and remote code execution on managed hosts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:71115** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71115)\n- **RHSA-2026:71114** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71114)\n- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)\n- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)\n- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}