RHSA-2026:71113CriticalCVSS 9.9

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

Published
September 23, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (60)

📋 Description

CVE-2026-12564 — Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-71458 — automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration CVE-2026-71459 — automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure CVE-2026-71460 — automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/ CVE-2026-71462 — automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on control pod CVE-2026-71463 — automation-controller: automation-controller-container: automation-controller: Notification template Jinja whitelist bypass via conditional gating leaks tracebacks CVE-2026-71464 — automation-controller: automation-controller-container: automation-controller: Schedule and WorkflowJobTemplateNode scm_branch prompt bypasses leading-dash git-argument guard CVE-2026-71465 — automation-controller: automation-controller-container: automation-controller: Ad-hoc command limit field allows CLI argument injection into ansible executable CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization CVE-2026-75884 — awx: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84470 — automation-controller: automation-controller-container: automation-controller/AWX: Bulk Job Launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass CVE-2026-84474 — automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match CVE-2026-84486 — automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS) CVE-2026-84499 — automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message CVE-2026-84502 — automation-controller: automation-controller-container: automation-controller: Project scm_url argument injection into git ls-remote --upload-pack yields RCE on the controller-task control-plane pod CVE-2026-84638 — automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution CVE-2026-84643 — automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant CVE-2026-84644 — automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process) CVE-2026-84679 — automation-controller: automation-controller-container: automation-controller: the AWX_TASK_ENV setting applies arbitrary environment variables to the control-plane web and task processes, enabling TLS interception of external credentials and code execution CVE-2026-84680 — automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token CVE-2026-84683 — automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover CVE-2026-84684 — automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them CVE-2026-84686 — automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS and Grafana credentials CVE-2026-84689 — automation-controller: automation-controller-container: automation-controller: bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations CVE-2026-84691 — automation-controller: automation-controller-container: automation-controller: format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator CVE-2026-84692 — automation-controller: automation-controller-container: automation-controller: workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's job template with the victim's credentials (cross-tenant privilege escalation) CVE-2026-84703 — automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry credential (cross-tenant credential disclosure) CVE-2026-84706 — automation-controller: automation-controller-container: automation-controller: Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment CVE-2026-84707 — automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure) CVE-2026-84708 — automation-controller: automation-controller-container: automation-controller: container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false (control-plane secret and identity compromise) CVE-2026-84709 — automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/ CVE-2026-84711 — automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise CVE-2026-84712 — automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership CVE-2026-84714 — automation-controller: automation-controller: incomplete sanitize_jinja() regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution environment CVE-2026-84716 — automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-CA certificates for caller-chosen (and case-variant impersonating) hostnames CVE-2026-84717 — automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in Bitbucket Data Center webhook receiver enumerates webhook-enabled job templates CVE-2026-84718 — automation-controller: automation-controller: client IP spoofing in audit/access logs via unrestricted X-Forwarded-For trust CVE-2026-84719 — automation-controller: automation-controller: WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane) CVE-2026-84720 — automation-controller: automation-controller: WorkflowJobNode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via ORM-traversal count-oracle CVE-2026-84724 — automation-controller: automation-controller: SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation

🎯 Affected products99

  • Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • aap-metrics-utility-0:2.6.20260923-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • aap-metrics-utility-0:2.6.20260923-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • aap-metrics-utility-0:2.6.20260923-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • aap-metrics-utility-0:2.6.20260923-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • aap-metrics-utility-0:2.6.20260923-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.17-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.17-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.17-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.17-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.17-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-cli-0:4.7.17-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-server-0:4.7.17-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-ui-0:4.7.17-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.17-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.17-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.17-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.17-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-0:1.2.13-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-0:1.2.13-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-base-0:1.2.13-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-base-services-0:1.2.13-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-event-stream-services-0:1.2.13-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-worker-services-0:1.2.13-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-0:2.6.20260923-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-0:2.6.20260923-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-config-0:2.6.20260923-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-proxy-0:2.6.17-3.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-proxy-0:2.6.17-3.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • +69 more not shown

✅ Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Restrict network egress from controller pods using Kubernetes NetworkPolicy to prevent outbound connections to untrusted destinations. Only allow connections to known Vault server endpoints. - Review and restrict the RBAC permissions of the automation-controller service account to follow the principle of least privilege. Remove unnecessary secret read access. - In AAP Cloud environments, audit credential-creation activity for suspicious HashiCorp Vault credentials with external or unusual URLs. - Monitor Kubernetes audit logs for unexpected API calls using the automation-controller service account, particularly secret reads and pod operations from EE pods. - Rotate the automation-controller service account token if unauthorized access is suspected. - Consider restricting the "create credential" privilege to only trusted administrators until the fix is available. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this issue, ensure that applications using GitPython's Repo.clone_from() method to clone from untrusted sources operate within a process environment that does not contain sensitive information as environment variables. Alternatively, implement strict validation and sanitization of all Git repository URLs before they are passed to Repo.clone_from() to prevent the inclusion of environment variable tokens. If the application is a service, a restart may be required for environment variable changes to take effect. Workaround: To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame(). Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To mitigate this vulnerability, avoid using DOMPurify with a custom IN_PLACE sanitization configuration that includes an element-removal hook. Default DOMPurify configurations are not affected by this flaw. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: - Restrict who holds the System Auditor role and avoid combining it with job-template execute grants; review custom roles that pair read on instance groups with execute on job templates. - Where feasible, restrict access to the Bulk Job Launch endpoint (/api/v2/bulk/job_launch/) at the network/proxy layer to trusted automation callers until the fix is applied. - Audit workflow/bulk jobs for placement onto instance groups the launching principal does not hold use_role on. Workaround: - Restrict who holds view_jobtemplate on job templates that have provisioning callback enabled; disable provisioning callback (clear host_config_key) on JTs that do not require it. - Set PROXY_IP_ALLOWED_LIST to the AAP gateway/envoy address(es) so untrusted client X-Forwarded-For headers are stripped before host matching. - Rotate any host_config_key values that may have been exposed to read-only users; review activity_stream access. - Monitor for jobs with launch_type=callback and unexpected limit values or created_by=None.

🔗 References (65)