CVE-2026-84724

MEDIUM CVSS 3.1: 6.6 EPSS 0.29%
Updated Sep 27, 2026
Red Hat
Parameter Value
CVSS 6.6 (MEDIUM)
Type CWE-88
Vendor Red Hat
Public PoC No

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments — including Python's path option — into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path.

Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat ansible automation platform 2.7 red hat:red hat ansible automation platform 2.6 for rhel 9 red hat:red hat ansible automation platform 2.6 red hat:red hat ansible automation platform 2.5 for rhel 8 red hat:red hat ansible automation platform 2.5 for rhel 9