Impact
A flaw in Red Hat Ansible Automation Platform's automation‑controller allows an authenticated user with only read permission to an instance group to attach that group to a schedule or a workflow job template node. The controller checks only that the user can read the instance group, instead of verifying that the user also has "use" permission. Because of this missing authorization, the user can link restricted or control‑plane instance groups to runs they control. When the playbook is executed, it runs on the control‑plane node or another tenant’s environment, enabling the attacker to achieve privilege escalation and potentially full control of the platform.
Affected Systems
Red Hat Ansible Automation Platform version 2.4 for EL8 and EL9 and version 2.6 for EL9 are affected. Users of these releases should verify the installed version against the vendor release notes for a fix.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, indicating critical impact. EPSS data is not available, but the severity remains high; the vulnerability is not listed in the CISA KEV catalog. An attacker only needs to be an authenticated user who can view an instance group, such as a system auditor, to exploit the flaw via the controller’s API relationship endpoint. By attaching a restricted instance group to a schedule or workflow node, the attacker can cause playbooks to run with higher privileges, leading to privilege escalation and, if the control‑plane group is used, full compromise of the automation platform.
OpenCVE Enrichment