---
id: CVE-2026-85475
title: A flaw was found in the Ansible Automation Platform automation controller
summary: >-
  A flaw was found in the Ansible Automation Platform automation controller. The

  external logging (rsyslog) configuration is generated by interpolating

  user-controlled settings — LOG_AGGREGATOR_HOST,
  LOG_AGGREGATOR_MAX_DISK_USAGE_PATH

  and …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-96
vendor: Red Hat
product: ansible-automation-platform-27/controller-rhel9
affected:
  - ansible-automation-platform-27/controller-rhel9 (all versions)
  - automation-controller (all versions)
patched:
  - ansible_automation_platform 2.7
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:17:46.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85475'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:71177'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-85475'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2528255'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85475.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-85475'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85475'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T14:33:34.362171Z'
ingestedAt: '2026-09-23T20:32:10.754Z'
epss: 0.00431
epssPercentile: 0.34745
---

## Overview

A flaw was found in the Ansible Automation Platform automation controller. The
external logging (rsyslog) configuration is generated by interpolating
user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH
and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config
file without neutralizing RainerScript syntax. A privileged (superuser) user can
inject rsyslog directives, including an omprog action, causing arbitrary command
execution inside the control-plane rsyslog component. This allows disclosure of
the controller SECRET_KEY and database credentials, decryption of all stored
credentials, and full compromise of the control plane.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)
- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2 · no fix planned: Red Hat Ansible Automation Platform 2 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85475.json)
