/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/c
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96442 | 7.8 HIGH | Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-96445 | 6.8 MEDIUM | Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against |
| CVE-2026-88839 | 6.7 MEDIUM | Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale toke |
| CVE-2026-88837 | 6.5 MEDIUM | Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting aut |
| CVE-2026-88835 | 6.1 MEDIUM | Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-boun |
| CVE-2026-88840 | 5.3 MEDIUM | Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clien |
| CVE-2026-88831 | 5.3 MEDIUM | Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix |
| CVE-2026-71458 | 5.0 MEDIUM | Automation-controller: automation-controller-container: automation-controller: named-url 4 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet