---
id: CVE-2026-84474
title: |-
  A flaw was found in Red Hat Ansible Automation Platform's automation-
  controller
summary: |-
  A flaw was found in Red Hat Ansible Automation Platform's automation-
  controller. The provisioning-callback secret (host_config_key) is exposed to
  users holding only the read-level view_jobtemplate permission -- both in the
  job template …
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-807
vendor: Red Hat
product: automation-controller
affected:
  - automation-controller (all versions)
  - automation-controller (all versions)
  - automation-controller (all versions)
  - automation-controller (all versions)
  - automation-controller (all versions)
  - ansible-automation-platform-26/controller-rhel9 (all versions)
  - ansible-automation-platform-27/controller-rhel9 (all versions)
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T06:17:01.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84474'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71114'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71115'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71177'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-84474'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2527073'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-84474.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-84474'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84474'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T19:28:08.444949Z'
ingestedAt: '2026-09-23T19:31:04.469Z'
patched:
  - ansible_automation_platform_2_4_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_4_for_rhel 9
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
epss: 0.00801
epssPercentile: 0.54685
---

## Overview

A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host_config_key) is exposed to
users holding only the read-level view_jobtemplate permission -- both in the
job template API representation and in the activity stream -- and the
provisioning callback endpoint trusts a client-supplied X-Forwarded-For
header to determine the calling host when the controller is deployed behind
the AAP gateway with an empty proxy allow-list. By reading the secret and
spoofing X-Forwarded-For to match any host in the job template's inventory, a
minimally privileged or unauthenticated remote attacker can launch the job
template against arbitrary managed hosts using the job template's credentials,
resulting in privilege escalation and remote code execution on managed hosts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:71115** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71115)
- **RHSA-2026:71114** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71114)
- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)
