Description
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching an instance group to a schedule or a workflow job
template node through the dedicated API relationship endpoint, the controller
verifies only that the requesting user can read (view) the instance group,
rather than that they hold use permission on it, unlike every other instance
group assignment in the product. An authenticated user with read-only
visibility of an instance group -- for example a system auditor -- can attach a
use-restricted instance group, including the control plane group or another
tenant's container group, to a schedule or workflow node they control. Their
playbook then executes on the control plane node or within another tenant's
execution environment, leading to privilege escalation and, in the control
plane case, full compromise of the platform.
Published: n/a
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A flaw in Red Hat Ansible Automation Platform's automation‑controller allows an authenticated user with only read permission to an instance group to attach that group to a schedule or a workflow job template node. The controller checks only that the user can read the instance group, instead of verifying that the user also has "use" permission. Because of this missing authorization, the user can link restricted or control‑plane instance groups to runs they control. When the playbook is executed, it runs on the control‑plane node or another tenant’s environment, enabling the attacker to achieve privilege escalation and potentially full control of the platform.

Affected Systems

Red Hat Ansible Automation Platform version 2.4 for EL8 and EL9 and version 2.6 for EL9 are affected. Users of these releases should verify the installed version against the vendor release notes for a fix.

Risk and Exploitability

The vulnerability has a CVSS score of 9.9, indicating critical impact. EPSS data is not available, but the severity remains high; the vulnerability is not listed in the CISA KEV catalog. An attacker only needs to be an authenticated user who can view an instance group, such as a system auditor, to exploit the flaw via the controller’s API relationship endpoint. By attaching a restricted instance group to a schedule or workflow node, the attacker can cause playbooks to run with higher privileges, leading to privilege escalation and, if the control‑plane group is used, full compromise of the automation platform.

Generated by OpenCVE AI on September 24, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a Red Hat Ansible Automation Platform release that corrects the authorization check on instance‑group assignments.
  • Restrict "use" permissions for instance groups so that only privileged users can link them to schedules or workflow nodes; ensure that read‑only or auditor roles do not have the ability to create or modify schedules.
  • Review existing schedules and workflow templates to confirm that no restricted or control‑plane instance groups are attached, and remediate any that are.
  • Enforce least‑privilege on user roles by removing unnecessary read‑only users from the set of entities that can create or edit schedules or workflow nodes.

Generated by OpenCVE AI on September 24, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Ansible Automation Platform's automation- controller. When attaching an instance group to a schedule or a workflow job template node through the dedicated API relationship endpoint, the controller verifies only that the requesting user can read (view) the instance group, rather than that they hold use permission on it, unlike every other instance group assignment in the product. An authenticated user with read-only visibility of an instance group -- for example a system auditor -- can attach a use-restricted instance group, including the control plane group or another tenant's container group, to a schedule or workflow node they control. Their playbook then executes on the control plane node or within another tenant's execution environment, leading to privilege escalation and, in the control plane case, full compromise of the platform.
Title automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-863
CPEs cpe:/a:redhat:ansible_automation_platform:2.4::el8
cpe:/a:redhat:ansible_automation_platform:2.4::el9
cpe:/a:redhat:ansible_automation_platform:2.6::el9
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Critical


Subscriptions

Redhat Ansible Automation Platform
cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-23T00:00:00Z

Links: CVE-2026-84638 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T01:30:12Z

Weaknesses