Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84470— Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Ansible Automation Platform 的 automation-controller(AWX)中发现一个缺陷。 批量任务启动 API(POST /api/v2/bulk/job_launch/)在授权请求的实例组时,仅执行了“读”级别的权限检查,而标准的单任务启动路径则要求对同一字段拥有“使用”(use)级别的权限。因此,拥有实例组的“读”权限(而非“使用”权限)——例如内置的只读系统审计员(System Auditor)角色——并同时拥有某个任务模板的执行权限的主体,可以将批量任务启动到他们

CVSS 6.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84470

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-84470

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84470

登录查看更多情报信息。

Other References for CVE-2026-84470 (2)

Same Patch Batch · Red Hat · 2026-09-01 · 11 CVEs total

CVE-2026-84268 8.8 HIGH Gvfs: sftp: heap-based buffer overflow in read_reply()
CVE-2026-84218 8.1 HIGH Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve
CVE-2026-49329 7.5 HIGH Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language hea
CVE-2026-84233 7.0 HIGH Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filena
CVE-2026-84269 6.5 MEDIUM Gvfs: afp: heap-based buffer overflow in dsi read path
CVE-2026-11873 6.5 MEDIUM Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java
CVE-2026-84232 5.4 MEDIUM Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded ht
CVE-2026-53682 5.3 MEDIUM Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts
CVE-2026-84270 4.3 MEDIUM Gvfs: mtp: out-of-bounds read in do_read()
CVE-2026-84267 4.3 MEDIUM Gvfs: sftp: uninitialized heap disclosure in read_string()

IV. Related Vulnerabilities

V. Comments for CVE-2026-84470

No comments yet


Leave a comment