Description
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.realpath), and it performs no containment check on
symlink-typed directory members before creating them. A crafted collection
tarball can chain symlink directory entries so that a subsequent file member is
written outside the intended destination directory. This allows an attacker who
can get a victim to install a malicious collection to overwrite arbitrary files
with the privileges of the user running ansible-galaxy, leading to code
execution on the control node. This is a bypass of the fix for CVE-2020-10691.
Published: 2026-10-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.
Title Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution
First Time appeared Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat ansible Core
Redhat ansible Portal
Redhat certifications
Redhat discovery
Redhat enterprise Linux
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openstack
Redhat rhui
Redhat satellite
Redhat service Mesh
Weaknesses CWE-59
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:ansible_core:2
cpe:/a:redhat:ansible_portal:2
cpe:/a:redhat:certifications:9
cpe:/a:redhat:discovery:2::el9
cpe:/a:redhat:migration_toolkit_applications:8
cpe:/a:redhat:migration_toolkit_virtualization:2
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:rhui:5::el9
cpe:/a:redhat:satellite:6
cpe:/a:redhat:service_mesh:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat ansible Core
Redhat ansible Portal
Redhat certifications
Redhat discovery
Redhat enterprise Linux
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openstack
Redhat rhui
Redhat satellite
Redhat service Mesh
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Acm Ansible Automation Platform Ansible Core Ansible Portal Certifications Discovery Enterprise Linux Migration Toolkit Applications Migration Toolkit Virtualization Openshift Openstack Rhui Satellite Service Mesh
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T21:49:30.953Z

Reserved: 2026-09-10T20:17:42.169Z

Link: CVE-2026-89091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T22:17:35.777

Modified: 2026-10-08T22:17:35.777

Link: CVE-2026-89091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')