CVE-2026-84719

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-24: 209-24
Referenced assets3 URLs
Full discourse2 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 UPDATE: RED HAT ANSIBLE AUTOMATION PLATFORM — SECOND CRITICAL (CVE-2026-84719) + PUBLISHED FIXES FOR AAP 2.6 / 2.4 Following yesterday’s CVE-2026-84502 Critical post, Red Hat has now published the companion errata and a second Critical controller flaw that operators should treat as part of the same patch cycle. • CVE-2026-84719 — CVSS 9.9 Critical — WorkflowJobTemplate /copy/ deep-copy sanitizer omitted InstanceGroup use_role checks, so a workflow-admin could pin jobs onto unauthorized instance groups, including the control-plane group • CVE-2026-84502 — CVSS 9.9 Critical — remains in scope (previously covered): privilege escalation via the controller API • Fixes published: AAP 2.6 RHSA-2026:71113 (automation-controller 4.7.17); AAP 2.4 RHSA-2026:71115 (automation-controller 4.5.36) • AAP 2.6 carries a large Critical RHSA batch; AAP 2.4 receives the high-impact subset • No confirmed in-the-wild exploitation is called out in the RHSA notes reviewed here ⚠️ Analyst Note: This is an UPDATE to the earlier single-CVE post, not a rehash. The new signal is CVE-2026-84719 plus the published RHSA fix streams for both supported AAP trains. Controllers that were only tracked against 84502 should still be upgraded using the errata above. Official Red Hat: https://access.redhat.com/errata/RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71115 https://access.redhat.com/security/cve/cve-2026-84719 #RedHat #Ansible #AAP #CVE202684719 #CVE202684502 #Critical #RCE #ThreatIntel #DDW

    121856.3K
    204.9K followersView on X
  • CCB Alert@CCBalert

    Warning: Multiple critical vulnerabilities in #RedHat Ansible Automation Platform (CVE-2026-84719, CVE-2026-84474, CVE-2026-84502, CVE-2026-75884, CVE-2026-12564)! CVSS up to 9.9. Can lead to privilege escalation and #RCE. #Patch #Patch #Patch

    02000271
    7.3K followersView on X

Explore more