Impact
Ansible Automation Platform's control plane accepts arbitrary environment variables via the AWX_TASK_ENV setting without validation. An administrator with system‐level privileges can inject variables such as REQUESTS_CA_BUNDLE or LD_PRELOAD, which are applied directly to the web and task processes. This flaw allows silent TLS credential interception, extraction of session keys, and potential native code execution in the control‑plane process, effectively elevating an application administrator to full control of the platform and all tenant secrets.
Affected Systems
Red Hat Ansible Automation Platform version 2.6 running on Enterprise Linux 9 hosts is affected. The flaw is located in the automation‑controller component and impacts the control‑plane web and task services that run within the container.
Risk and Exploitability
With a CVSS score of 8.7, this vulnerability is considered high severity. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attack requires a user with system administrator role to modify AWX_TASK_ENV; the attacker can then execute arbitrary code on the control plane and compromise all tenant secrets. Because the vector involves administrative configuration rather than external network input, the likelihood of exploitation depends on the internal threat model and access controls.
OpenCVE Enrichment