← Back to search

CVE-2026-84502

9.9 CRITICAL

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an attacker to inject arbitrary commands via the scm_url field, leading to remote code execution on the control-plane task pod.
Exploitability
Exploitation requires write access to a project in a single organization and knowledge of the specific URL format to trigger the vulnerability. It is moderately hard to exploit.
Blast radius
If exploited, the attacker can execute arbitrary commands on the control-plane task pod, potentially leading to cross-tenant compromise and in-cluster lateral movement.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Red Hat Ansible Automation Platform 2.590 or later.
rcewebgiturl-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by git as the --upload-pack option and executed via a shell. A user with permission to create or modify a project in a single organization can thereby execute arbitrary commands on the control-plane task pod, with output reflected through the project update stdout endpoint, leading to cross-tenant compromise and in-cluster lateral movement

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-88

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.