Skip to content

RHSA 2026:71113

access.redhat.com September 24, 2026

Critical: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

An update is now available for Red Hat Ansible Automation Platform 2.6

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to , vet, and manage automation content by means of a simple, powerful, and agentless language.

automation-controller: GitPython: Remote Code Execution via Git directory impersonation (CVE-2026-87817)

automation-controller: Job template enumeration via unauthenticated Bitbucket webhook oracle (CVE-2026-84717)

automation-controller: Command argument injection via SystemJob extra_vars (CVE-2026-84724)

automation-controller: Masked credential data disclosure via workflow job node artifact (CVE-2026-84720)

automation-controller: Instance-group privilege escalation via workflow job template copy (CVE-2026-84719)

automation-controller: Audit log falsification via unrestricted X-Forwarded-For trust (CVE-2026-84718)

automation-controller: Mesh certificate issuance for arbitrary hostnames via install bundle (CVE-2026-84716)

automation-controller: Template injection via sanitize_jinja regex bypass (CVE-2026-84714)

automation-controller: Automation mesh topology disclosure via unauthenticated ping endpoint (CVE-2026-84712)

automation-controller: Arbitrary file read via Project scm_branch git argument injection (CVE-2026-84711)

automation-controller: Denial of service via credential type injector Jinja rendering (CVE-2026-84709)

automation-controller: Control-plane secret exposure via container group pod spec override (CVE-2026-84708)

automation-controller: Unauthorized job output disclosure via host filter query traversal (CVE-2026-84707)

automation-controller: Code execution via credential type environment-injector blocklist bypass (CVE-2026-84706)

automation-controller: Cross-tenant credential exposure via execution environment binding (CVE-2026-84703)

automation-controller: Cross-tenant execution privilege bypass via workflow job template node patch (CVE-2026-84692)

automation-controller: Secret key and database credential disclosure via format-string injection (CVE-2026-84691)

automation-controller: Cross-tenant job hijack via Bulk Job Launch node reference (CVE-2026-84689)

automation-controller: Credential token disclosure via notification template type-switch replay (CVE-2026-84686)

automation-controller: Privilege escalation via constructed inventory attachment (CVE-2026-84684)

automation-controller: Stored cross-site scripting via ANSI hyperlink sequence in job output (CVE-2026-84683)

automation-controller: Credential-use privilege escalation via organization Galaxy credential attachment (CVE-2026-84680)

automation-controller: Arbitrary environment variable injection via AWX_TASK_ENV setting (CVE-2026-84679)

automation-controller: Server-side request forgery via Thycotic Secret Server credential test (CVE-2026-84644)

automation-controller: Cross-organization credential exposure via Project signature-validation binding (CVE-2026-84643)

automation-controller: Instance-group privilege escalation via Schedule and workflow node attachment (CVE-2026-84638)

automation-controller: Remote code execution via Project scm_url git argument injection (CVE-2026-84502)

automation-controller: Survey password disclosure via validation error message (CVE-2026-84499)

automation-controller: Unauthenticated scheduler-trigger endpoint exposure (regression) (CVE-2026-84486)

automation-controller: Privilege escalation via provisioning-callback host-match bypass (CVE-2026-84474)

automation-controller: Instance-group privilege escalation via Bulk Job Launch permission check (CVE-2026-84470)

automation-controller: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)

automation-controller: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups (CVE-2026-75884)

automation-controller: Command-line argument injection via ad hoc command limit field (CVE-2026-71465)

automation-controller: Git argument-injection guard bypass via Schedule scm_branch prompt (CVE-2026-71464)

automation-controller: Stack trace disclosure via notification-template Jinja whitelist bypass (CVE-2026-71463)

automation-controller: Filesystem path-existence oracle via CUSTOM_VENV_PATHS validation (CVE-2026-71462)

automation-controller: Cross-tenant job event data exposure via missing RBAC check (CVE-2026-71459)

automation-controller: Cross-tenant resource enumeration via Named-URL 404 response oracle (CVE-2026-71458)

automation-controller: Unrestricted subscription and license information disclosure (CVE-2026-71460)

automation-controller: GitPython: Command Injection via Git option prefix abbreviation (CVE-2026-67325)

automation-controller: GitPython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323)

automation-controller: GitPython: Environment variable exfiltration via attacker-controlled clone URL (CVE-2026-67322)

automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF (CVE-2026-12564)

automation-gateway-proxy: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)

automation-gateway-proxy: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)

automation-gateway-proxy: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)

automation-gateway-proxy: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

automation-gateway-proxy: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)

automation-platform-ui: js-yaml: Denial of Service vulnerability in YAML parsing (CVE-2026-84375)

automation-platform-ui: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization (CVE-2026-75838)

automation-platform-ui: nanoid: Denial of Service via negative size input in non-secure module functions (CVE-2026-67214)

automation-platform-ui: nanoid: Predictable ID generation due to integer overflow (CVE-2026-73086)

automation-platform-ui: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

automation-platform-ui: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869)

python-sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284)

python-sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893)

python-sqlparse: Denial of Service via quadratic CPU consumption in grouping (CVE-2026-71491)

python3.12-gitpython: Remote Code Execution via Git directory impersonation (CVE-2026-87817)

python3.12-sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing (CVE-2026-54284)

python3.12-sqlparse: Denial of Service via inefficient SQL parsing (CVE-2026-59893)

python3.12-sqlparse: Denial of Service via quadratic CPU consumption in grouping (CVE-2026-71491)

receptor: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

receptor: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

receptor: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)

receptor: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)

receptor: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)

receptor: Go net/ http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)

For more details the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

For details this release, refer to the release notes listed in the References section.

For details on how to apply this update, refer to Ansible Automation Platform documentation.

Red Hat Ansible Automation Platform 2.6 for RHEL 10 x86_64

Red Hat Ansible Automation Platform 2.6 for RHEL 10 s390x

Red Hat Ansible Automation Platform 2.6 for RHEL 10 ppc64le

Red Hat Ansible Automation Platform 2.6 for RHEL 10 aarch64

Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64

Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x

Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le

Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64

Red Hat Ansible Inside 1.4 x86_64

Red Hat Ansible Inside 1.4 s390x

Red Hat Ansible Inside 1.4 ppc64le

Red Hat Ansible Inside 1.4 aarch64

Red Hat Ansible Developer 1.3 for RHEL 10 x86_64

Red Hat Ansible Developer 1.3 for RHEL 10 s390x

Red Hat Ansible Developer 1.3 for RHEL 10 ppc64le

Red Hat Ansible Developer 1.3 for RHEL 10 aarch64

Red Hat Ansible Developer 1.3 for RHEL 9 x86_64

Red Hat Ansible Developer 1.3 for RHEL 9 s390x

Red Hat Ansible Developer 1.3 for RHEL 9 ppc64le

Red Hat Ansible Developer 1.3 for RHEL 9 aarch64

BZ - 2484204 - CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header

BZ - 2490556 - CVE-2026-12564 Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF

BZ - 2498122 - CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents

BZ - 2508411 - CVE-2026-67214 nanoid: nanoid: Denial of Service via negative size input in non-secure module functions

BZ - 2509975 - CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation

BZ - 2509976 - CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options

BZ - 2510021 - CVE-2026-67322 gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL

BZ - 2510719 - CVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURL

BZ - 2512367 - CVE-2026-71458 automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration

BZ - 2512368 - CVE-2026-71459 automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure

BZ - 2512369 - CVE-2026-71460 automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/

BZ - 2512371 - CVE-2026-71462 automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on control pod

BZ - 2512372 - CVE-2026-71463 automation-controller: automation-controller-container: automation-controller: Notification template Jinja whitelist bypass via conditional gating leaks tracebacks

BZ - 2512374 - CVE-2026-71464 automation-controller: automation-controller-container: automation-controller: Schedule and WorkflowJobTemplateNode scm_branch prompt bypasses leading-dash git-argument guard

BZ - 2512375 - CVE-2026-71465 automation-controller: automation-controller-container: automation-controller: Ad-hoc command limit field allows CLI argument injection into ansible executable

BZ - 2514175 - CVE-2026-73086 nanoid: nanoid: Predictable ID generation due to integer overflow

BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal

BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution

BZ - 2515827 - CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service

BZ - 2515838 - CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input

BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

BZ - 2515840 - CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue

BZ - 2517518 - CVE-2026-71491 sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in grouping

BZ - 2517523 - CVE-2026-59893 sqlparse: sqlparse: Denial of Service via inefficient SQL parsing

BZ - 2517527 - CVE-2026-54284 sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing

BZ - 2517772 - CVE-2026-75838 dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization

BZ - 2517893 - CVE-2026-75884 awx: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups

BZ - 2523205 - CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create()

BZ - 2527046 - CVE-2026-84470 automation-controller: automation-controller-container: automation-controller/AWX: Bulk Job Launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass

BZ - 2527073 - CVE-2026-84474 automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match

BZ - 2527085 - CVE-2026-84486 automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS)

BZ - 2527090 - CVE-2026-84499 automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message

BZ - 2527096 - CVE-2026-84502 automation-controller: automation-controller-container: automation-controller: Project scm_url argument injection into `git ls-remote --upload-pack` yields RCE on the controller-task control-plane pod

BZ - 2527100 - CVE-2026-84638 automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) ...

BZ - 2527112 - CVE-2026-84643 automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization ...

BZ - 2527117 - CVE-2026-84644 automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the co ...

BZ - 2527118 - CVE-2026-84375 js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

BZ - 2527123 - CVE-2026-84679 automation-controller: automation-controller-container: automation-controller: the AWX_TASK_ENV setting applies arbitrary environment variables to the control-plane web and task processes, enabling TLS interception of external credentia ...

BZ - 2527126 - CVE-2026-84680 automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and ...

BZ - 2527128 - CVE-2026-84683 automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover

BZ - 2527139 - CVE-2026-84684 automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hos ...

BZ - 2527140 - CVE-2026-84686 automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plai ...

BZ - 2527145 - CVE-2026-84689 automation-controller: automation-controller-container: automation-controller: bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of job ...

BZ - 2527151 - CVE-2026-84691 automation-controller: automation-controller-container: automation-controller: format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator

BZ - 2527154 - CVE-2026-84692 automation-controller: automation-controller-container: automation-controller: workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single work ...

BZ - 2527156 - CVE-2026-84703 automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another ...

BZ - 2527187 - CVE-2026-84706 automation-controller: automation-controller-container: automation-controller: Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment

BZ - 2527189 - CVE-2026-84707 automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind charact ...

BZ - 2527190 - CVE-2026-84708 automation-controller: automation-controller-container: automation-controller: container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing au ...

BZ - 2527191 - CVE-2026-84709 automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled ...

BZ - 2527195 - CVE-2026-84711 automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials ...

BZ - 2527196 - CVE-2026-84712 automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership

BZ - 2527198 - CVE-2026-84714 automation-controller: automation-controller: incomplete sanitize_jinja() regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution enviro ...

BZ - 2527199 - CVE-2026-84716 automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-CA certificates for caller-chosen (and case-variant impersonating) hostnames

BZ - 2527210 - CVE-2026-84717 automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in Bitbucket Data Center webhook receiver enumerates webhook-enabled job templates

BZ - 2527211 - CVE-2026-84718 automation-controller: automation-controller: client IP spoofing in audit/access logs via unrestricted X-Forwarded-For trust

BZ - 2527213 - CVE-2026-84719 automation-controller: automation-controller: WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane)

BZ - 2527214 - CVE-2026-84720 automation-controller: automation-controller: WorkflowJobNode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via ORM-traversal count-oracle

BZ - 2527222 - CVE-2026-84724 automation-controller: automation-controller: SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process

BZ - 2530744 - CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation

Red Hat Ansible Automation Platform 2.6 for RHEL 10

Red Hat Ansible Automation Platform 2.6 for RHEL 9

Red Hat Ansible Inside 1.4

Red Hat Ansible Developer 1.3 for RHEL 10

Red Hat Ansible Developer 1.3 for RHEL 9

The Red Hat security is [email protected] . More details at .