Description
A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,
unified_job_template, and credentials of each cloned node and fails to check the instance_groups
(and execution_environment and labels) that were preserved from the original. A user with
organization workflow-admin permission but no role on the referenced instance groups can copy a
workflow, become its administrator, and launch jobs pinned to instance groups they are not
authorized to use — including the control-plane instance group — bypassing the InstanceGroup
use_role boundary and causing attacker-influenced automation to run in the control-plane
execution context.
Published: 2026-09-23
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Privilege escalation to control‑plane execution
Action: Immediate Patch
AI Analysis

Impact

A bug in the automation-controller of Red Hat Ansible Automation Platform 2 allows an attacker with workflow‑admin rights to copy a workflow job template without being subject to instance_group permissions that were inherited from the original. The deep‑copy sanitizer validates only the inventory, unified_job_template, and credentials fields, neglecting instance_groups (plus execution_environment and labels). As a result, the attacker can become the administrative owner of the cloned workflow and launch jobs that target instance groups, including the control‑plane, that they are not authorized to use. This bypass of the InstanceGroup use_role check is a classic authorization flaw (CWE‑862) that can let attacker‑influenced automation run with full control‑plane privileges.

Affected Systems

The affected product is Red Hat Ansible Automation Platform 2 supplied by Red Hat. All releases of the 2.x branch that include the automation‑controller component are impacted until the vendor releases a patch. No specific sub‑version detail is given, so the entire 2 branch is considered vulnerable.

Risk and Exploitability

The vulnerability scores a CVSS of 9.9, indicating high severity. EPSS is not available, but the absence of a listing in the CISA KEV catalog does not diminish the risk; the flaw can be exploited by any user with workflow‑admin rights and no instance‑group role, a capability that many administrators possess. The attack is likely to be internal or privileged, requiring possession of a valid account that is granted workflow‑admin. Once exploited, the attacker can execute arbitrary automation tasks in the control‑plane context, potentially altering system state, compromising data, or creating persistence.

Generated by OpenCVE AI on September 23, 2026 at 20:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Red Hat patch that addresses CVE‑2026‑84719 by upgrading to the latest Ansible Automation Platform 2 release
  • Restrict workflow‑admin permissions to only those users who also have appropriate instance_group roles, especially for the control‑plane; ensure no workflow‑admin can copy templates that reference protected instance groups unless explicitly authorized
  • Audit existing workflow job templates after patch deployment to verify that all cloned instances correctly inherit instance_group authorizations and do not bypass the check; use the platform’s audit logs to confirm that no uncontrolled instance_group usage exists

Generated by OpenCVE AI on September 23, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
CPEs cpe:/a:redhat:ansible_automation_platform:2.4::el8
cpe:/a:redhat:ansible_automation_platform:2.4::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9
Vendors & Products Redhat ansible Automation Platform Developer
References

Wed, 23 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.
Title Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-862
CPEs cpe:/a:redhat:ansible_automation_platform:2
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Ansible Automation Platform Ansible Automation Platform Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-23T21:47:44.874Z

Reserved: 2026-09-02T01:20:53.823Z

Link: CVE-2026-84719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T20:17:18.617

Modified: 2026-09-23T20:17:18.617

Link: CVE-2026-84719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:45:09Z

Weaknesses