← Back to search

CVE-2026-84719

9.9 CRITICAL

Published 2026-09-23 · Updated 2026-09-25

AI risk analysis

Summary
The flaw in Ansible Automation Platform allows a user with workflow-admin permission to copy a WorkflowJobTemplate and launch jobs in unauthorized instance groups, including the control-plane, bypassing security boundaries.
Exploitability
Exploitation is moderately hard as it requires the user to have workflow-admin permission and knowledge of the instance groups involved. Precondition is the presence of instance groups with different access controls.
Blast radius
If exploited, this could lead to unauthorized execution of jobs in sensitive instance groups, potentially compromising the control-plane and other critical infrastructure.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Ansible Automation Platform 2.590 or later.
auth-bypassautomationcontrol-plane

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.