Skip to main content
Vulnerability Database/CVE-2026-84502

CVE-2026-84502: Red Hat Ansible Automation Platform RCE

CVE-2026-84502 is a remote code execution flaw in Red Hat Ansible Automation Platform that allows attackers to execute arbitrary commands via malicious git project URLs. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-84502 Overview

CVE-2026-84502 is an argument injection vulnerability in Red Hat Ansible Automation Platform's automation-controller. The Project scm_url field is not validated against values that begin with a dash. The unsanitized value is passed verbatim to the git Source Control Management (SCM) module. Because the module runs git ls-remote with the URL as a positional argument and without a -- separator, a crafted URL such as --upload-pack=<command>:x is interpreted by git as the --upload-pack option and executed through a shell. Any authenticated user with permission to create or modify a project within a single organization can execute arbitrary commands on the control-plane task pod. The flaw is classified under CWE-88: Improper Neutralization of Argument Delimiters.

Critical Impact

A low-privileged tenant user can achieve arbitrary command execution on the shared control-plane task pod, enabling cross-tenant compromise and in-cluster lateral movement.

Affected Products

  • Red Hat Ansible Automation Platform — automation-controller component
  • Red Hat Ansible Automation Platform 2.4
  • Red Hat Ansible Automation Platform 2.5

Discovery Timeline

  • 2026-09-23 - CVE-2026-84502 published to the National Vulnerability Database (NVD)
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-84502

Vulnerability Analysis

The defect lies in how automation-controller handles the Project scm_url input before invoking git. The value is stored and forwarded without normalization or validation of leading characters. When the git SCM module executes git ls-remote <scm_url>, git treats any argument beginning with - as an option rather than a positional URL. Attackers weaponize this by supplying --upload-pack=<command> style values, which git passes to a shell during remote enumeration. Output from the injected command is reflected back through the project update stdout endpoint, giving attackers an interactive feedback channel.

Because the task pod runs shared workloads across organizations, command execution on that pod breaks the tenant isolation boundary. Attackers can then read secrets, credentials, and other tenants' inventories, and pivot to adjacent services inside the Kubernetes cluster.

Root Cause

The root cause is missing argument delimiter handling. The git invocation omits the -- end-of-options marker before the URL, and the application layer performs no rejection of values that start with -. Together these two omissions allow argument injection into a downstream command that reaches a shell.

Attack Vector

Exploitation requires authenticated access with permission to create or modify a Project in one organization. The attacker submits a malicious scm_url value beginning with --upload-pack= and triggers a project update. The task pod executes the attacker-supplied command and returns output through the standard project update log endpoint. No user interaction on the victim side is required, and the vector is network-reachable through the standard automation-controller API and UI.

See the Red Hat CVE Report for CVE-2026-84502 and Red Hat Bug Report #2527096 for the vendor's technical narrative.

Detection Methods for CVE-2026-84502

Indicators of Compromise

  • Project records or audit entries where scm_url begins with -, particularly values containing --upload-pack=, --receive-pack=, or --config=.
  • Project update stdout output containing shell command results, environment variables, or file contents unrelated to git repository metadata.
  • Unexpected outbound network connections, reverse shells, or DNS lookups originating from the automation-controller task pod.
  • New or modified files under service-account writable paths on the task pod, including .ssh/authorized_keys and Kubernetes service-account token reads.

Detection Strategies

  • Inspect automation-controller audit logs and the Project API for any historical or current scm_url values matching the pattern ^-.
  • Alert on git ls-remote process invocations on task pods where the URL argument begins with - or contains upload-pack.
  • Monitor Kubernetes API activity from the task pod service account for anomalous secrets, configmaps, or pods/exec calls.
  • Baseline expected child processes of the task pod container and alert on shells (sh, bash) spawned as descendants of git operations.

Monitoring Recommendations

  • Forward automation-controller application logs, project update stdout, and Kubernetes audit logs to a centralized analytics platform for correlation.
  • Track project creation and modification events by user, organization, and source IP to identify low-privileged accounts probing the scm_url field.
  • Enable egress network logging on task pods and alert on connections to non-repository destinations during project sync operations.

How to Mitigate CVE-2026-84502

Immediate Actions Required

  • Apply the fixed automation-controller packages from the Red Hat Security Advisories listed below.
  • Audit all existing Projects for scm_url values beginning with - and quarantine or delete offending records before patching.
  • Rotate credentials, tokens, and SSH keys that were reachable from the automation-controller task pod, including Kubernetes service-account tokens.
  • Review project update logs across all organizations for evidence of command output reflected through stdout.

Patch Information

Red Hat has published fixes through multiple advisories. Consult the advisory matching your product channel and apply the corresponding errata:

Workarounds

  • Restrict the admin and Project Admin roles so that untrusted or low-trust users cannot create or modify Projects in any organization.
  • Implement an admission or proxy control that rejects Project create and update API requests where scm_url begins with -.
  • Isolate the automation-controller task pod with Kubernetes NetworkPolicies limiting egress to approved SCM endpoints only.
  • Enforce least-privilege Kubernetes RBAC on the task pod service account to reduce blast radius if command execution occurs.
bash
# Configuration example: identify vulnerable Project scm_url values via the awx CLI
awx projects list -f json \
  | jq '.results[] | select(.scm_url | startswith("-")) | {id, name, organization, scm_url}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.