Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.6epss 0.3%
probabilidad de explotación
0.3%top 81% de las CVE
explotación observada
noninguna fuente lo reporta
An argument-injection flaw was found in the Ansible Automation Platform automation-controller
system-job subsystem. The system-job template launch endpoint stores a user-supplied "days"
variable without running the integer validation defined elsewhere for that field, and the
dispatcher flattens the management-command argument list into a single string with spaces before
the job runner re-splits it, so spaces in the value become additional command-line arguments.
Because system jobs are executed in-process on the control node without the container isolation
applied to all other job types, an authenticated user with superuser privileges can inject
arbitrary arguments — including Python's path option — into the control-plane awx-manage process,
controlling its argument vector and the first entry of its module search path. Full remote code
execution requires an additional import gadget that is not present in the current management
commands, so the demonstrated impact is argument injection with control of the process search
path rather than confirmed code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Productos afectados
Red Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8Red Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 9Red Hat · Red Hat Ansible Automation Platform 2.6Red Hat · Red Hat Ansible Automation Platform 2.6 for RHEL 9Red Hat · Red Hat Ansible Automation Platform 2.7Referencias
https://access.redhat.com/errata/RHSA-2026:71113https://access.redhat.com/errata/RHSA-2026:71114https://access.redhat.com/errata/RHSA-2026:71177https://access.redhat.com/errata/RHSA-2026:71179https://access.redhat.com/security/cve/CVE-2026-84724https://bugzilla.redhat.com/show_bug.cgi?id=2527222