Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84706— Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Ansible Automation Platform 的 automation-controller 中发现了一个漏洞。该漏洞源于自定义“凭证类型(Credential Type)”的环境变量注入器在验证变量名时,仅依赖一个黑名单机制(包括以 为前缀的检查以及一个固定的 列表),但该黑名单遗漏了可用于进程劫持的加载器变量,例如 、 、 、 、 和 。 结合凭证文件注入功能,攻击者可以诱导特权用户将恶意脚本写入执行环境,并通过设置 变量指向该脚本,从而在对任意附加该类型凭证的作业执行过程中,在“执行环境容器(e

CVSS 7.6 · High EPSS 0.31% · P21
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84706

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.33-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:4.7.17-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2.6 1789673739 ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el9
Red Hat Red Hat Ansible Automation Platform 2.7 1789580684 ~ * cpe:/a:redhat:ansible_automation_platform:2.7::el9

II. Public POCs for CVE-2026-84706

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84706

请登录查看更多情报信息。

Other References for CVE-2026-84706 (6)

Same Patch Batch · Red Hat · 2026-09-23 · 46 CVEs total

CVE-2026-84474 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: view_jobtem
CVE-2026-84502 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: project scm
CVE-2026-84719 9.9 CRITICAL Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz
CVE-2026-75884 9.1 CRITICAL Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c
CVE-2026-96275 8.8 HIGH Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-84691 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: format stri
CVE-2026-84683 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: stored cros
CVE-2026-76648 8.5 HIGH Automation-controller: automation-controller-container: aap controller: copyapiview.post()
CVE-2026-84486 8.2 HIGH Automation-controller: automation-controller-container: automation-controller: unauthentic
CVE-2026-96512 7.8 HIGH Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori
CVE-2026-96889 7.8 HIGH Librsvg: use-after-free when xml includes have duplicated entities
CVE-2026-84499 7.7 HIGH Automation-controller: automation-controller-container: automation-controller: write-only
CVE-2026-96541 7.5 HIGH Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d
CVE-2026-75887 7.5 HIGH Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle
CVE-2026-88830 7.5 HIGH Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr
CVE-2026-88832 7.3 HIGH Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label
CVE-2026-85475 7.2 HIGH Automation-controller: automation-controller-container: automation-controller: rsyslog con
CVE-2026-75886 7.2 HIGH Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd
CVE-2026-84714 7.1 HIGH Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin
CVE-2026-96445 6.8 MEDIUM Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-84706

No comments yet


Leave a comment