
🚨 RED HAT ANSIBLE AUTOMATION PLATFORM CVSS 9.9 — LOW-PRIVILEGE PROJECT USER CAN REACH CONTROL-PLANE RCE Red Hat disclosed CVE-2026-84502, a critical argument-injection flaw in Ansible Automation Platform's automation-controller that can turn permission to manage a project into arbitrary command execution on the controller task pod. • CVE-2026-84502 — CVSS 9.9 Critical • The vulnerable scm_url project field accepts values beginning with a dash and passes them directly to git ls-remote without a -- separator • A crafted project URL can be interpreted by Git as the --upload-pack option rather than as a repository URL • The attacker-controlled value is executed through a shell on the control-plane task pod • Exploitation requires an authenticated user with permission to create or modify a project in only a single organization — not platform administrator access • Command output can be recovered through the project-update stdout endpoint • Red Hat warns the flaw can lead to cross-tenant compromise and lateral movement inside the cluster • No public PoC or confirmed in-the-wild exploitation identified at this time ⚠️ Analyst Note: The privilege-boundary failure is what makes this significant. A tenant-scoped Ansible user who should only configure a project can potentially cross into the automation control plane. Controllers commonly hold privileged credentials and orchestrate infrastructure across many systems, so control-plane RCE can have a substantially larger blast radius than compromise of an ordinary application container. Primary: https://access.redhat.com/security/cve/CVE-2026-84502 Errata: https://access.redhat.com/errata/RHSA-2026:71115 #Ansible #RedHat #CVE202684502 #RCE #DevOps #Automation #CloudSecurity #ThreatIntel #DDW #DarkWeb

