Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84714— Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 automation-controller 的输入验证防护机制 中发现了一个漏洞。该函数使用两个正则表达式来拒绝用户提供的 Jinja 表达式,但这些模式的匹配在遇到第一个内部的 或 字符时就会停止,因此包含内部大括号(例如空字典)的 Jinja 表达式会被接受,同时仍然保持为有效的 Jinja 语法。由于 是多个启动时字段(如 ad-hoc 命令的 module_args、机器凭据的 username / become_method / become_user,以及清单主机名称)的唯一防护机制,低权限用户可以

CVSS 7.1 · High EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84714

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitize_jinja() is the sole guard on several launch-time fields — ad-hoc command module_args, Machine-credential username / become_method / become_user, and inventory host names — a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's AD_HOC_COMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.33-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:4.7.17-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2.6 1789673739 ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el9
Red Hat Red Hat Ansible Automation Platform 2.7 1789580684 ~ * cpe:/a:redhat:ansible_automation_platform:2.7::el9

II. Public POCs for CVE-2026-84714

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84714

请登录查看更多情报信息。

Other References for CVE-2026-84714 (6)

Same Patch Batch · Red Hat · 2026-09-23 · 46 CVEs total

CVE-2026-84474 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: view_jobtem
CVE-2026-84502 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: project scm
CVE-2026-84719 9.9 CRITICAL Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz
CVE-2026-75884 9.1 CRITICAL Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c
CVE-2026-96275 8.8 HIGH Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-84691 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: format stri
CVE-2026-84683 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: stored cros
CVE-2026-76648 8.5 HIGH Automation-controller: automation-controller-container: aap controller: copyapiview.post()
CVE-2026-84486 8.2 HIGH Automation-controller: automation-controller-container: automation-controller: unauthentic
CVE-2026-96512 7.8 HIGH Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori
CVE-2026-96889 7.8 HIGH Librsvg: use-after-free when xml includes have duplicated entities
CVE-2026-84499 7.7 HIGH Automation-controller: automation-controller-container: automation-controller: write-only
CVE-2026-84706 7.6 HIGH Automation-controller: automation-controller-container: automation-controller: credential
CVE-2026-96541 7.5 HIGH Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d
CVE-2026-75887 7.5 HIGH Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle
CVE-2026-88830 7.5 HIGH Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr
CVE-2026-88832 7.3 HIGH Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label
CVE-2026-75886 7.2 HIGH Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd
CVE-2026-85475 7.2 HIGH Automation-controller: automation-controller-container: automation-controller: rsyslog con
CVE-2026-96445 6.8 MEDIUM Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-84714

No comments yet


Leave a comment