CVE-2026-84474 Overview
CVE-2026-84474 is a flaw in Red Hat Ansible Automation Platform's automation-controller component. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission, appearing in both the job template API representation and the activity stream. The provisioning callback endpoint also trusts a client-supplied X-Forwarded-For header when the controller runs behind the AAP gateway with an empty proxy allow-list. An attacker who reads the secret and spoofs X-Forwarded-For to match any host in the job template's inventory can launch the job template against arbitrary managed hosts using the job template's stored credentials.
Critical Impact
A minimally privileged or unauthenticated remote attacker can achieve privilege escalation and remote code execution on managed hosts by exploiting an exposed provisioning secret combined with header spoofing.
Affected Products
- Red Hat Ansible Automation Platform (automation-controller component)
- Deployments where automation-controller sits behind the AAP gateway with an empty proxy allow-list
- Job templates configured with provisioning callbacks enabled
Discovery Timeline
- 2026-09-23 - CVE-2026-84474 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-84474
Vulnerability Analysis
The vulnerability chains two distinct weaknesses in automation-controller to enable remote code execution on managed hosts. The first weakness is an information disclosure: the host_config_key, which authenticates provisioning callback requests, is returned in job template API responses and written to the activity stream. Any user with view_jobtemplate permission can read it, even though the secret is intended to be treated as a credential.
The second weakness is reliance on an attacker-controlled input. When automation-controller sits behind the AAP gateway with no proxy allow-list configured, the provisioning callback endpoint uses the X-Forwarded-For header to identify the calling host. An attacker sets this header to any managed host in the job template's inventory, then submits the leaked host_config_key. The controller launches the job template against the spoofed host using credentials stored in the template, yielding code execution under those credentials.
Root Cause
The root cause is reliance on untrusted inputs in a security decision, tracked as [CWE-807]. The provisioning callback trusts a client-supplied HTTP header for host identity, and the API returns a callback secret to users who should only hold read access to job template metadata.
Attack Vector
Exploitation requires network access to the AAP gateway. An attacker with view_jobtemplate permission queries the job template API or activity stream to retrieve the host_config_key. The attacker then issues a POST request to the provisioning callback endpoint with a spoofed X-Forwarded-For header referencing a target host from the template's inventory. The controller executes the job template's playbook against that host using the credentials attached to the template. See the Red Hat CVE details for the full technical write-up.
Detection Methods for CVE-2026-84474
Indicators of Compromise
- Provisioning callback jobs launched from unexpected source IP addresses or with X-Forwarded-For values that do not match trusted proxy infrastructure.
- API access logs showing GET requests to job template endpoints or the activity stream by low-privilege accounts, followed by callback endpoint activity.
- Unscheduled job template executions targeting managed hosts outside normal provisioning windows.
Detection Strategies
- Correlate automation-controller audit logs for reads of job template objects with subsequent provisioning callback invocations from the same or related source.
- Alert on any provisioning callback request where the X-Forwarded-For header originates outside the configured proxy chain.
- Baseline normal callback frequency per job template and flag deviations, particularly bursts against multiple inventory hosts.
Monitoring Recommendations
- Forward automation-controller and AAP gateway access logs to a centralized SIEM for retention and correlation.
- Monitor managed hosts for unexpected ansible process execution or new SSH sessions originating from the controller outside scheduled windows.
- Review activity stream access patterns weekly to identify low-privilege accounts enumerating job template metadata.
How to Mitigate CVE-2026-84474
Immediate Actions Required
- Apply the Red Hat security updates referenced in advisories RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71115, RHSA-2026:71177, and RHSA-2026:71179.
- Rotate every host_config_key value that existed before patching, since the secret may have been read by any user with view_jobtemplate permission.
- Audit job template permissions and revoke view_jobtemplate from accounts that do not require it.
Patch Information
Red Hat has released fixed builds of automation-controller through the advisories listed above. Refer to the Red Hat CVE page and Bugzilla #2527073 for the complete list of affected packages and fixed versions per AAP release stream.
Workarounds
- Disable provisioning callbacks on job templates that do not require them until patches are applied.
- Configure a strict proxy allow-list on the AAP gateway so X-Forwarded-For is only honored from trusted upstream proxies.
- Restrict network access to the provisioning callback endpoint to known provisioning subnets using firewall or ingress controls.
# Configuration example - restrict callback endpoint at the ingress
# and configure a non-empty proxy allow-list on the AAP gateway.
# Refer to the Red Hat advisories for the authoritative settings:
# https://access.redhat.com/security/cve/CVE-2026-84474
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
