{"id":"CVE-2026-84474","published":"2026-09-23T19:19:39.930","lastModified":"2026-09-24T06:17:01.990","description":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. The provisioning-callback secret (host_config_key) is exposed to\nusers holding only the read-level view_jobtemplate permission -- both in the\njob template API representation and in the activity stream -- and the\nprovisioning callback endpoint trusts a client-supplied X-Forwarded-For\nheader to determine the calling host when the controller is deployed behind\nthe AAP gateway with an empty proxy allow-list. By reading the secret and\nspoofing X-Forwarded-For to match any host in the job template's inventory, a\nminimally privileged or unauthenticated remote attacker can launch the job\ntemplate against arbitrary managed hosts using the job template's credentials,\nresulting in privilege escalation and remote code execution on managed hosts.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-807"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71115","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71177","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71179","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-84474","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527073","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a minimally privileged or unauthenticated attacker to read a secret and launch job templates against arbitrary hosts, leading to privilege escalation and remote code execution.","exploitability":"Exploitation is moderately hard as it requires reading the secret and spoofing the X-Forwarded-For header, but the preconditions are minimal.","blast_radius":"If exploited, the impact is severe, as it can lead to full control over managed hosts and potential data exfiltration or destruction.","remediation":"Disable the provisioning-callback feature or restrict access to the provisioning callback endpoint to only trusted sources.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","secret-exposure","api-security","privilege-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:48:07.282Z"}}