{"id":"CVE-2026-84719","published":"2026-09-23T20:17:18.617","lastModified":"2026-09-25T19:17:58.367","description":"A flaw was found in the Ansible Automation Platform automation-controller. When a\nWorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,\nunified_job_template, and credentials of each cloned node and fails to check the instance_groups\n(and execution_environment and labels) that were preserved from the original. A user with\norganization workflow-admin permission but no role on the referenced instance groups can copy a\nworkflow, become its administrator, and launch jobs pinned to instance groups they are not\nauthorized to use — including the control-plane instance group — bypassing the InstanceGroup\nuse_role boundary and causing attacker-influenced automation to run in the control-plane\nexecution context.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71115","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71177","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71179","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-84719","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527213","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in Ansible Automation Platform allows a user with workflow-admin permission to copy a WorkflowJobTemplate and launch jobs in unauthorized instance groups, including the control-plane, bypassing security boundaries.","exploitability":"Exploitation is moderately hard as it requires the user to have workflow-admin permission and knowledge of the instance groups involved. Precondition is the presence of instance groups with different access controls.","blast_radius":"If exploited, this could lead to unauthorized execution of jobs in sensitive instance groups, potentially compromising the control-plane and other critical infrastructure.","remediation":"Upgrade to Ansible Automation Platform 2.590 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","automation","control-plane"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:48:17.999Z"}}