Skip to content
ThreatCluster

Argument Injection Vulnerability in Ansible Automation Platform

First seen 24 Sep 2026, 01:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 02:27 UTC

An argument-injection flaw (CVE-2026-84724) was identified in the Ansible Automation Platform's automation-controller system-job subsystem. This vulnerability allows authenticated users with superuser privileges to inject arbitrary arguments into the control-plane awx-manage process due to a lack of integer validation on a user-supplied variable. The flaw arises from the way the system-job template launch endpoint processes the 'days' variable, which is not validated properly before being flattened into a command string. While full remote code execution is not currently possible without additional conditions, the flaw enables control over the argument vector and module path. The vulnerability affects users of the Ansible Automation Platform, particularly those utilizing the automation-controller. A fix has been proposed that includes shlex-safe quoting and validation of the launch-time variables. The CVE was published on September 23, 2026, and is now included in the NVD dataset.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
CVE-2026-84724 published
The vulnerability was officially published to the CVE List and included in the NVD dataset.
Nvd.Nist
2026-09-24
Red Hat issues advisory
Red Hat provided details on the argument injection flaw and proposed a fix for the vulnerability.
access.redhat.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-12564 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed