CVE-2026-84474
9.9Red Hat · Ansible Automation Platform
A flaw in Red Hat Ansible Automation Platform allows remote attackers to bypass security controls, leading to privilege escalation and remote code execution on managed hosts.
Executive summary
A critical vulnerability in Red Hat Ansible Automation Platform allows unauthorized users to execute arbitrary code on managed hosts by exploiting improper secret exposure and trust in untrusted HTTP headers.
Vulnerability
This vulnerability involves the exposure of sensitive provisioning callback secrets to low-privileged users and the improper validation of X-Forwarded-For headers. By spoofing the header and leveraging the exposed secret, an attacker can trigger unauthorized job template execution on managed infrastructure.
Business impact
The potential for remote code execution on managed hosts represents a catastrophic risk, as it allows attackers to gain full control over the automated infrastructure. Given the CVSS score of 9.9, this vulnerability poses an extreme threat to organizational security, enabling lateral movement, data exfiltration, or complete system compromise across the managed environment.
Remediation
Immediate Action: Update your Red Hat Ansible Automation Platform environment to the fixed versions specified in the Red Hat Security Advisories (RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71115, RHSA-2026:71177, or RHSA-2026:71179) immediately.
Proactive Monitoring: Review activity streams and API access logs for unauthorized access to job templates or suspicious X-Forwarded-For header values.
Compensating Controls: Ensure the AAP gateway is properly configured with a strict proxy allow-list to prevent the acceptance of spoofed host identification headers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is critical and requires immediate attention due to the high risk of remote code execution on managed assets. System administrators must prioritize patching the Ansible Automation Platform components to the versions listed in the vendor advisory to eliminate the underlying secret exposure and header spoofing vulnerabilities. Delaying remediation exposes the entire managed infrastructure to potential compromise.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by This issue was discovered by Chris Meyers (Red Hat)., per the CVE Program record.
- RHSA-2026:71113 Vendor advisory
- RHSA-2026:71114 Vendor advisory
- RHSA-2026:71115 Vendor advisory
- RHSA-2026:71177 Vendor advisory
- RHSA-2026:71179 Vendor advisory
- Vulnerability database entry
- RHBZ#2527073 Issue tracker