CVE-2026-84718
4.3 MEDIUMPublished 2026-09-23 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-348
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100653PoC
- MEDIUMCVE-2026-101277
- MEDIUMCVE-2026-102275PoC
- CRITICALCVE-2026-61682PoC
- MEDIUMCVE-2026-62987PoC
- MEDIUMCVE-2026-80514
- MEDIUMCVE-2026-87070
- CRITICALCVE-2026-92395PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.