Ad

CVE-2026-84706

HIGH CVSS 3.1: 7,6 EPSS 0.31%
Обновлено 27 сентября 2026
Red Hat
Параметр Значение
CVSS 7,6 (HIGH)
Тип уязвимости CWE-184
Поставщик Red Hat
Публичный эксплойт Нет

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Высокие
Нужны права администратора
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Низкое
Частичная утечка данных
Целостность
Высокое
Полная модификация данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Тип уязвимости (CWE)

Уязвимые продукты

red hat:red hat ansible automation platform 2.7 red hat:red hat ansible automation platform 2.6 for rhel 9 red hat:red hat ansible automation platform 2.6 red hat:red hat ansible automation platform 2.5 for rhel 8 red hat:red hat ansible automation platform 2.5 for rhel 9