---
cve: "CVE-2026-84474"
severity: "CRITICAL"
cvss: 9.9
epss: ""
vendor: "Red Hat"
kev: false
exploited: false
published: "2026-09-23 19:19:39"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T08:45:04+02:00"
---

# CVE-2026-84474

> 9.9 CRITICAL

## Beschreibung

A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host_config_key) is exposed to
users holding only the read-level view_jobtemplate permission -- both in the
job template API representation and in the activity stream -- and the
provisioning callback endpoint trusts a client-supplied X-Forwarded-For
header to determine the calling host when the controller is deployed behind
the AAP gateway with an empty proxy allow-list. By reading the secret and
spoofing X-Forwarded-For to match any host in the job template's inventory, a
minimally privileged or unauthenticated remote attacker can launch the job
template against arbitrary managed hosts using the job template's credentials,
resulting in privilege escalation and remote code execution on managed hosts.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3555) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.

## Referenzen

- <https://access.redhat.com/errata/RHSA-2026:71113>
- <https://access.redhat.com/errata/RHSA-2026:71114>
- <https://access.redhat.com/errata/RHSA-2026:71115>
- <https://access.redhat.com/errata/RHSA-2026:71177>
- <https://access.redhat.com/errata/RHSA-2026:71179>
- <https://access.redhat.com/security/cve/CVE-2026-84474>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2527073>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-84474) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
