CRITICAL 9.9 NVD
CVE-2026-84474
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host_config_key) is exposed to
users holding only the read-level view_jobtemplate permission -- both in the
job template API representation and in the activity stream -- and the
provisioning callback endpoint trusts a client-supplied X-Forwarded-For
header to determine the calling host when the controller is deployed behind
the AAP gateway with an empty proxy allow-list. By reading the secret and
spoofing X-Forwarded-For to match any host in the job template's inventory, a
minimally privileged or unauthenticated remote attacker can launch the job
template against arbitrary managed hosts using the job template's credentials,
resulting in privilege escalation and remote code execution on managed hosts.
References
- https://access.redhat.com/errata/RHSA-2026:71113
- https://access.redhat.com/errata/RHSA-2026:71115
- https://access.redhat.com/security/cve/CVE-2026-84474
- https://bugzilla.redhat.com/show_bug.cgi?id=2527073
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-09-23 via NVD.
Risk Timeline
CVE Disclosed2026-09-23 · -1 days ago
Remediation Resources
Official Advisory
access.redhat.com/errata/RHSA-2026:71113Official Advisory
access.redhat.com/errata/RHSA-2026:71115Analysis & PoC
bugzilla.redhat.com/show_bug.cgi?id=2527073
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.