Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84720— Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Ansible Automation Platform 的 automation-controller 中发现了一个安全漏洞。WorkflowJobNode 表的 数据库列用于存储在工作流节点之间传播的原始合并的 工件。该列未被 函数包裹保护,因此尽管它在 API 序列化器中被省略(即不通过 API 暴露),REST 过滤器后端仍接受对该列的任意字段查询。 由于该列在 Ansible 的 屏蔽机制应用之前就被持久化存储到数据库中,导致具有工作流只读权限的用户,或者任何通过世界可读的 端点绕过 JSON 跨关系过

CVSS 6.5 · Medium EPSS 0.27% · P17
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84720

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST filter backend, even though it is omitted from the API serializer. Because the column is persisted before Ansible's no_log masking is applied, a user with only read access to a workflow — or, via a regular-expression lookup that bypasses the JSON cross-relation filter guard through the world-readable credential-types endpoint, any authenticated user with no roles — can use the result count as a boolean/count oracle to recover, character by character, secret values that a playbook author explicitly marked no_log, including across organizations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.33-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:4.7.17-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2.6 1789673739 ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el9
Red Hat Red Hat Ansible Automation Platform 2.7 1789580684 ~ * cpe:/a:redhat:ansible_automation_platform:2.7::el9

II. Public POCs for CVE-2026-84720

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84720

请登录查看更多情报信息。

Other References for CVE-2026-84720 (6)

Same Patch Batch · Red Hat · 2026-09-23 · 46 CVEs total

CVE-2026-84474 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: view_jobtem
CVE-2026-84502 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: project scm
CVE-2026-84719 9.9 CRITICAL Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz
CVE-2026-75884 9.1 CRITICAL Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c
CVE-2026-96275 8.8 HIGH Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-84691 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: format stri
CVE-2026-84683 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: stored cros
CVE-2026-76648 8.5 HIGH Automation-controller: automation-controller-container: aap controller: copyapiview.post()
CVE-2026-84486 8.2 HIGH Automation-controller: automation-controller-container: automation-controller: unauthentic
CVE-2026-96512 7.8 HIGH Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori
CVE-2026-96889 7.8 HIGH Librsvg: use-after-free when xml includes have duplicated entities
CVE-2026-84499 7.7 HIGH Automation-controller: automation-controller-container: automation-controller: write-only
CVE-2026-84706 7.6 HIGH Automation-controller: automation-controller-container: automation-controller: credential
CVE-2026-96541 7.5 HIGH Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d
CVE-2026-75887 7.5 HIGH Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle
CVE-2026-88830 7.5 HIGH Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr
CVE-2026-88832 7.3 HIGH Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label
CVE-2026-85475 7.2 HIGH Automation-controller: automation-controller-container: automation-controller: rsyslog con
CVE-2026-75886 7.2 HIGH Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd
CVE-2026-84714 7.1 HIGH Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-84720

No comments yet


Leave a comment