Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84716— Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 automation-controller 实例的 端点中发现了一个漏洞。当系统管理员下载执行节点或跳步节点的安装包时,控制器会使用受管网格(receptor mesh)的证书颁发机构对 X.509 证书进行签名。该证书中的通用名称(Common Name)、DNS 主题备用名称(DNS subject-alternative-name)以及 receptor 节点 ID 均直接从调用方选择的实例主机名中按字面获取,证书有效期硬编码为十年,序列号为随机生成,且没有颁发日志或吊销列表。 由于主机名字符集验证器是不

CVSS 6.6 · Medium EPSS 0.18% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84716

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments — where the customer holds controller superuser but the platform operator runs the mesh — this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.33-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:4.7.17-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2.6 1789673739 ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el9
Red Hat Red Hat Ansible Automation Platform 2.7 1789580684 ~ * cpe:/a:redhat:ansible_automation_platform:2.7::el9

II. Public POCs for CVE-2026-84716

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84716

请登录查看更多情报信息。

Other References for CVE-2026-84716 (6)

Same Patch Batch · Red Hat · 2026-09-23 · 46 CVEs total

CVE-2026-84474 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: view_jobtem
CVE-2026-84502 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: project scm
CVE-2026-84719 9.9 CRITICAL Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz
CVE-2026-75884 9.1 CRITICAL Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c
CVE-2026-96275 8.8 HIGH Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-84691 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: format stri
CVE-2026-84683 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: stored cros
CVE-2026-76648 8.5 HIGH Automation-controller: automation-controller-container: aap controller: copyapiview.post()
CVE-2026-84486 8.2 HIGH Automation-controller: automation-controller-container: automation-controller: unauthentic
CVE-2026-96512 7.8 HIGH Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori
CVE-2026-96889 7.8 HIGH Librsvg: use-after-free when xml includes have duplicated entities
CVE-2026-84499 7.7 HIGH Automation-controller: automation-controller-container: automation-controller: write-only
CVE-2026-84706 7.6 HIGH Automation-controller: automation-controller-container: automation-controller: credential
CVE-2026-96541 7.5 HIGH Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d
CVE-2026-75887 7.5 HIGH Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle
CVE-2026-88830 7.5 HIGH Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr
CVE-2026-88832 7.3 HIGH Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label
CVE-2026-85475 7.2 HIGH Automation-controller: automation-controller-container: automation-controller: rsyslog con
CVE-2026-75886 7.2 HIGH Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd
CVE-2026-84714 7.1 HIGH Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-84716

No comments yet


Leave a comment