A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an ar
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96442 | 7.8 HIGH | Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-96445 | 6.8 MEDIUM | Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against |
| CVE-2026-88839 | 6.7 MEDIUM | Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale toke |
| CVE-2026-88837 | 6.5 MEDIUM | Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting aut |
| CVE-2026-88835 | 6.1 MEDIUM | Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-boun |
| CVE-2026-88840 | 5.3 MEDIUM | Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clien |
| CVE-2026-88831 | 5.3 MEDIUM | Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix |
| CVE-2026-71459 | 5.0 MEDIUM | Automation-controller: automation-controller-container: automation-controller: jobjobevent |
| CVE-2026-71458 | 5.0 MEDIUM | Automation-controller: automation-controller-container: automation-controller: named-url 4 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet