RHSA-2026:71177CriticalCVSS 9.9

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

Published
September 23, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (61)

📋 Description

CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-71458 — automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration CVE-2026-71459 — automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure CVE-2026-71460 — automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/ CVE-2026-71461 — automation-controller: automation-controller-container: automation-controller: Verbose internal exception disclosure via HostList bare-Exception handler CVE-2026-71462 — automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on control pod CVE-2026-71463 — automation-controller: automation-controller-container: automation-controller: Notification template Jinja whitelist bypass via conditional gating leaks tracebacks CVE-2026-71464 — automation-controller: automation-controller-container: automation-controller: Schedule and WorkflowJobTemplateNode scm_branch prompt bypasses leading-dash git-argument guard CVE-2026-71465 — automation-controller: automation-controller-container: automation-controller: Ad-hoc command limit field allows CLI argument injection into ansible executable CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-75884 — awx: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names CVE-2026-76648 — automation-controller: automation-controller-container: AAP Controller: CopyAPIView.post() missing read authorization check enables Job Template secret recovery CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create() CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84470 — automation-controller: automation-controller-container: automation-controller/AWX: Bulk Job Launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass CVE-2026-84474 — automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match CVE-2026-84475 — automation-controller: automation-controller-container: automation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle CVE-2026-84486 — automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS) CVE-2026-84499 — automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message CVE-2026-84502 — automation-controller: automation-controller-container: automation-controller: Project scm_url argument injection into git ls-remote --upload-pack yields RCE on the controller-task control-plane pod CVE-2026-84638 — automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution CVE-2026-84643 — automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant CVE-2026-84644 — automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process) CVE-2026-84678 — automation-controller: automation-controller-container: automation-controller: GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment CVE-2026-84680 — automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token CVE-2026-84683 — automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover CVE-2026-84684 — automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them CVE-2026-84686 — automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS and Grafana credentials CVE-2026-84689 — automation-controller: automation-controller-container: automation-controller: bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations CVE-2026-84691 — automation-controller: automation-controller-container: automation-controller: format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator CVE-2026-84692 — automation-controller: automation-controller-container: automation-controller: workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's job template with the victim's credentials (cross-tenant privilege escalation) CVE-2026-84703 — automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry credential (cross-tenant credential disclosure) CVE-2026-84706 — automation-controller: automation-controller-container: automation-controller: Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment CVE-2026-84707 — automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure) CVE-2026-84708 — automation-controller: automation-controller-container: automation-controller: container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false (control-plane secret and identity compromise) CVE-2026-84709 — automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/ CVE-2026-84711 — automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise CVE-2026-84712 — automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership CVE-2026-84713 — automation-controller: automation-controller: Notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle CVE-2026-84714 — automation-controller: automation-controller: incomplete sanitize_jinja() regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution environment CVE-2026-84716 — automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-CA certificates for caller-chosen (and case-variant impersonating) hostnames CVE-2026-84717 — automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in Bitbucket Data Center webhook receiver enumerates webhook-enabled job templates CVE-2026-84718 — automation-controller: automation-controller: client IP spoofing in audit/access logs via unrestricted X-Forwarded-For trust CVE-2026-84719 — automation-controller: automation-controller: WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane) CVE-2026-84720 — automation-controller: automation-controller: WorkflowJobNode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via ORM-traversal count-oracle CVE-2026-84721 — automation-controller: automation-controller: Email notification backend allows SSRF via user-controlled SMTP host/port (internal port-scan oracle, SMTP password exfil) CVE-2026-84724 — automation-controller: automation-controller: SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process CVE-2026-85475 — automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via LOG_AGGREGATOR_* settings leads to remote code execution in the control-plane rsyslog component CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation

🎯 Affected products63

  • Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:0b75a14b04e2acde8891c341741ad7ca6fe9a1cf813a219cf7fc0a84e75c1594_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:41e6f73fdb2e0a645dab3c1a39fd6d592ab065c57dc006c173b899dcdcb50849_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:6c9519df74c8abe56b3fcb40bfc69601c8b1e20334459d19dd43fd808ff1fa27_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:e5ad86a01687e66b4a554c961233f34230a12b57c10c0d6759d030ef45db1536_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:20682ea97fabb44f52d82361bd985d2e9b31d8e445c09b99ebf0acdbcfe5f210_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:9a83ad041e1635f5dd19961fecb86d264f3ed84dce46e0f12470e6899fe8d1d4_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:451dd49a0c6d2db9ee93eae11dbf22fa0141333065b446e23914d505ebacc49c_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:c6b1bafccf5f8ecbc14ded8e0248212580cea99f23c3b936761bfc047c18700a_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:8618b81a56dccc2fbccca159b85ffa3bec880e4cc153777c3436647f406d5214_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:f46585aa330968602c8271d2125d08c7707eb9deb6adb510eeb03228359a2a5f_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:0b4d286c39fbb3056643306df9e81c2d4727e005a551ab74c2cee0950f35bf25_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:e0a869c7abe2af122a5fcc06b7c4d9ca3eec2693dde7b58c9b9ccea27f71dc6c_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:22d8b62bc6c8fc6080ed1d865e8c1ff43ecae9e022f4129446880f420268b825_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:9e0dc59cf8257cd0110dcc290e802dd90d68a01673ec0bbe58b56cbb2232204f_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:1127a87b3076eb96d95173668ed45862717dcc5214fc115403994658b95d3016_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:d1f03165a19e5917e9e0b8aa346083040e20a4776b8bb3290c0e3a5a877d53c2_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:0d941dfc6092dd74957cc01b5ad1b1644c9a13c2c2a161e3d349933683e20c4d_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:c6b2fa9a7aab79b42af4c57eeb2716021dd5b6d7480fa601cb31cd9150c98818_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:482539b79cec97bfd76d8819fa619e4678853350a2ac84a6c92dd5b384379d24_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:6d8d36299f4927477ae24af1d4ff1652f38ac6a56b4a9579c7fb4b17c4f80a69_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:904f970a84ecab81d79d36b8c520661e98503abe285eae2dbf97b2cf4429f5ba_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:a0f659d2efd1d2617a3bc253eb209076dc81771f68d17a9f1766d06a993a3e02_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:7f96bd89a4856d830d0c0810c74d9c5788b3308d0e20ea9ad352c7a0e924a54d_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:9012fa0d25987b291930ebf0b14864eebccfe2ede365c0e218a117ff52a2d198_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:ac28d37c494276939650fd6d27d40abba6e8e52fae96a48a542b09366be9280b_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:c696e71172a6f1b1f184bea1030f73f5cec70a5d6d06abe428f58fea7013767f_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:12a27e330b7d8811e3696c61f35d80ad2aa3a5de024614a4eae0456c92b190fb_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:d97a6fc9c34132bfddf5c8f0db93a24fea67ed3db2094d15f78d7f4eba724f1f_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/gateway-proxy-rhel9@sha256:103ef9e0d88fa76c726edcbd778466c38f8e153fedcd924f3ff3bec52d4888a7_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • +33 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: - Restrict who holds the System Auditor role and avoid combining it with job-template execute grants; review custom roles that pair read on instance groups with execute on job templates. - Where feasible, restrict access to the Bulk Job Launch endpoint (/api/v2/bulk/job_launch/) at the network/proxy layer to trusted automation callers until the fix is applied. - Audit workflow/bulk jobs for placement onto instance groups the launching principal does not hold use_role on. Workaround: - Restrict who holds view_jobtemplate on job templates that have provisioning callback enabled; disable provisioning callback (clear host_config_key) on JTs that do not require it. - Set PROXY_IP_ALLOWED_LIST to the AAP gateway/envoy address(es) so untrusted client X-Forwarded-For headers are stripped before host matching. - Rotate any host_config_key values that may have been exposed to read-only users; review activity_stream access. - Monitor for jobs with launch_type=callback and unexpected limit values or created_by=None.

🔗 References (65)