CVE-2026-84706

HIGH CVSS 3.1: 7.6 EPSS 0.31%
Updated Sep 27, 2026
Red Hat
Parameter Value
CVSS 7.6 (HIGH)
Type CWE-184
Vendor Red Hat
Public PoC No

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat ansible automation platform 2.7 red hat:red hat ansible automation platform 2.6 for rhel 9 red hat:red hat ansible automation platform 2.6 red hat:red hat ansible automation platform 2.5 for rhel 8 red hat:red hat ansible automation platform 2.5 for rhel 9