Skip to main content
Vulnerability Database/CVE-2026-84474

CVE-2026-84474: Ansible Automation Platform Privilege Escalation

CVE-2026-84474 is a privilege escalation flaw in Red Hat Ansible Automation Platform that exposes provisioning-callback secrets and allows attackers to execute code on managed hosts. This article covers technical details, impact analysis, affected versions, and mitigation strategies.

Published:

CVE-2026-84474 Overview

CVE-2026-84474 is a flaw in Red Hat Ansible Automation Platform's automation-controller component. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission, appearing in both the job template API representation and the activity stream. The provisioning callback endpoint also trusts a client-supplied X-Forwarded-For header when the controller runs behind the AAP gateway with an empty proxy allow-list. An attacker who reads the secret and spoofs X-Forwarded-For to match any host in the job template's inventory can launch the job template against arbitrary managed hosts using the job template's stored credentials.

Critical Impact

A minimally privileged or unauthenticated remote attacker can achieve privilege escalation and remote code execution on managed hosts by exploiting an exposed provisioning secret combined with header spoofing.

Affected Products

  • Red Hat Ansible Automation Platform (automation-controller component)
  • Deployments where automation-controller sits behind the AAP gateway with an empty proxy allow-list
  • Job templates configured with provisioning callbacks enabled

Discovery Timeline

  • 2026-09-23 - CVE-2026-84474 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-84474

Vulnerability Analysis

The vulnerability chains two distinct weaknesses in automation-controller to enable remote code execution on managed hosts. The first weakness is an information disclosure: the host_config_key, which authenticates provisioning callback requests, is returned in job template API responses and written to the activity stream. Any user with view_jobtemplate permission can read it, even though the secret is intended to be treated as a credential.

The second weakness is reliance on an attacker-controlled input. When automation-controller sits behind the AAP gateway with no proxy allow-list configured, the provisioning callback endpoint uses the X-Forwarded-For header to identify the calling host. An attacker sets this header to any managed host in the job template's inventory, then submits the leaked host_config_key. The controller launches the job template against the spoofed host using credentials stored in the template, yielding code execution under those credentials.

Root Cause

The root cause is reliance on untrusted inputs in a security decision, tracked as [CWE-807]. The provisioning callback trusts a client-supplied HTTP header for host identity, and the API returns a callback secret to users who should only hold read access to job template metadata.

Attack Vector

Exploitation requires network access to the AAP gateway. An attacker with view_jobtemplate permission queries the job template API or activity stream to retrieve the host_config_key. The attacker then issues a POST request to the provisioning callback endpoint with a spoofed X-Forwarded-For header referencing a target host from the template's inventory. The controller executes the job template's playbook against that host using the credentials attached to the template. See the Red Hat CVE details for the full technical write-up.

Detection Methods for CVE-2026-84474

Indicators of Compromise

  • Provisioning callback jobs launched from unexpected source IP addresses or with X-Forwarded-For values that do not match trusted proxy infrastructure.
  • API access logs showing GET requests to job template endpoints or the activity stream by low-privilege accounts, followed by callback endpoint activity.
  • Unscheduled job template executions targeting managed hosts outside normal provisioning windows.

Detection Strategies

  • Correlate automation-controller audit logs for reads of job template objects with subsequent provisioning callback invocations from the same or related source.
  • Alert on any provisioning callback request where the X-Forwarded-For header originates outside the configured proxy chain.
  • Baseline normal callback frequency per job template and flag deviations, particularly bursts against multiple inventory hosts.

Monitoring Recommendations

  • Forward automation-controller and AAP gateway access logs to a centralized SIEM for retention and correlation.
  • Monitor managed hosts for unexpected ansible process execution or new SSH sessions originating from the controller outside scheduled windows.
  • Review activity stream access patterns weekly to identify low-privilege accounts enumerating job template metadata.

How to Mitigate CVE-2026-84474

Immediate Actions Required

  • Apply the Red Hat security updates referenced in advisories RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71115, RHSA-2026:71177, and RHSA-2026:71179.
  • Rotate every host_config_key value that existed before patching, since the secret may have been read by any user with view_jobtemplate permission.
  • Audit job template permissions and revoke view_jobtemplate from accounts that do not require it.

Patch Information

Red Hat has released fixed builds of automation-controller through the advisories listed above. Refer to the Red Hat CVE page and Bugzilla #2527073 for the complete list of affected packages and fixed versions per AAP release stream.

Workarounds

  • Disable provisioning callbacks on job templates that do not require them until patches are applied.
  • Configure a strict proxy allow-list on the AAP gateway so X-Forwarded-For is only honored from trusted upstream proxies.
  • Restrict network access to the provisioning callback endpoint to known provisioning subnets using firewall or ingress controls.
bash
# Configuration example - restrict callback endpoint at the ingress
# and configure a non-empty proxy allow-list on the AAP gateway.
# Refer to the Red Hat advisories for the authoritative settings:
# https://access.redhat.com/security/cve/CVE-2026-84474

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.