CVE-2026-84719
Last modified
CVE-2026-84719 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.4 for RHEL 8 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.4 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-84719?
How severe is CVE-2026-84719?
How do I fix CVE-2026-84719?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84713A flaw was found in the automation-controller notification …6.5
- CVE-2026-84714A flaw was found in the automation-controller input-validati…7.1
- CVE-2026-84715FeatherPanel versions before 1.3.7.10 fail to validate permi…8.8
- CVE-2026-84716A flaw was found in the automation-controller instance …6.6
- CVE-2026-84717A flaw was found in the Ansible Automation Platform automati…5.3
- CVE-2026-84718A flaw was found in the Ansible Automation Platform automati…4.3
- CVE-2026-8472GitLab has remediated an issue in GitLab EE affecting all ve…4.3
- CVE-2026-84720A flaw was found in the Ansible Automation Platform automati…6.5
- CVE-2026-84721A server-side request forgery flaw was found in the Ansible …6.4
- CVE-2026-84724An argument-injection flaw was found in the Ansible Automati…6.6
- CVE-2026-84732Retransmissions of ACK packet ID in OpenVPN through 2.6.22 a…8.7
- CVE-2026-84736In the current development version of Eclipse aeriOS, for wh…8.3
Are you affected by CVE-2026-84719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
