CVE-2026-84691
Last modified
CVE-2026-84691 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-84691?
How severe is CVE-2026-84691?
How do I fix CVE-2026-84691?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84676Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlie…4.3
- CVE-2026-84677Jenkins update-center2 3.18.3 and earlier does not escape pl…5.4
- CVE-2026-8468Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-84683A flaw was found in Red Hat Ansible Automation Platform's au…8.7
- CVE-2026-84685The react-native-auth0 SDK's web platform implementation doe…6.5
- CVE-2026-8469Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-84694Coolify before 4.2.0 fails to properly escape environment va…8.8
- CVE-2026-84695BookStack before 26.05.4 contains a stored cross-site script…8.7
- CVE-2026-84696Phison PS3111-S11 controller firmware versions through SBFQT…8.2
- CVE-2026-84697Mailpit's IsInternalIP deny list function fails to block the…5.3
- CVE-2026-84698PX4 Autopilot contains a heap buffer overflow vulnerability …6.5
- CVE-2026-84699Team Password Manager before 14.184.308 fails to enforce aut…9.1
Are you affected by CVE-2026-84691?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
