important · Privilege escalation
Read-only Ansible job-template access can launch stored automation against arbitrary managed hosts.
Affects
Red Hat Ansible Automation Platform automation-controller on RHEL and OpenShift, which runs stored jobs across managed infrastructure.
With AAP behind its gateway and the proxy allow-list empty, a template viewer can read the provisioning callback key, spoof X-Forwarded-For and launch the stored template against an attacker-selected inventory host using saved credentials. Red Hat has shipped updates.
Detail and 2 sources
Sources
ResearchRed Hat Ansible Automation Platform vulnerability cluster reaches controller code execution and tenant secretsResearch2527073 – (CVE-2026-84474) CVE-2026-84474 automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match