๐Ÿ” CVE Alert

CVE-2026-84724

MEDIUM 6.6

Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments โ€” including Python's path option โ€” into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.

CWE CWE-88
Vendor red hat
Product red hat ansible automation platform 2.6 for rhel 9
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat ansible automation platform 2.6 for rhel 9

Be the first to know when new medium vulnerabilities affecting red hat red hat ansible automation platform 2.6 for rhel 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Red Hat / Red Hat Ansible Automation Platform 2.6 for RHEL 9
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:71113 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-84724 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2527222