securityonline.info 24 Sept 2026, 03:28 UTC

Red Hat Fixes Critical Ansible Flaws Enabling Control Plane Takeover

Red Hat Fixes Critical Ansible Flaws Enabling Control Plane Takeover
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

RED Hat has disclosed two critical vulnerabilities in Ansible Automation Platform 2.4 for RHEL 8: CVE-2026-84719, rated 9.9, and CVE-2026-75884, rated 9.1 on CVSSv3. The article says neither flaw has been exploited, and no public proof-of-concept code has been confirmed. CVE-2026-75884 involves incomplete input validation in container-group configuration, allowing an administrator to inject overrides and escalate privileges to OpenShift namespace-level access.

This could expose sensitive information including administrator passwords and database encryption keys. Containerised Podman installations are described as unaffected by this flaw.

CVE-2026-84719 affects the automation-controller subsystem. When a workflow job template is copied, its deep-copy permission sanitiser fails to check authorisation for inherited instance groups. A user could therefore schedule jobs on restricted groups, including the control plane, potentially achieving arbitrary code execution in the control-plane execution context. The affected areas include the AWX controller and automation-controller subsystems, with standard cluster deployments exposed according to the report.

Red Hat has issued fixes, including 0:4.5.36-1.el8ap, 0:4.5.36-1.el9ap, 0:4.6.33-1.el8ap and 0:4.6.33-1.el9ap. Administrators should apply the vendor’s latest security updates.

View full article

Article by CyberSIXT