---
cve: "CVE-2026-84502"
severity: "CRITICAL"
cvss: 9.9
epss: "0.6%"
vendor: "Red Hat"
kev: false
exploited: false
published: "2026-09-23 18:47:26"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T07:26:10+02:00"
---

# CVE-2026-84502

> 9.9 CRITICAL

## Beschreibung

A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Project scm_url field is not validated against values that
begin with a dash and is stored and passed verbatim to the git SCM module.
Because the module runs git ls-remote with the URL as a positional argument and
without a "--" separator, a git project URL such as "--upload-pack=:x"
is interpreted by git as the --upload-pack option and executed via a shell. A
user with permission to create or modify a project in a single organization can
thereby execute arbitrary commands on the control-plane task pod, with output
reflected through the project update stdout endpoint, leading to cross-tenant
compromise and in-cluster lateral movement

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3555) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.

## Referenzen

- <https://access.redhat.com/errata/RHSA-2026:71113>
- <https://access.redhat.com/errata/RHSA-2026:71114>
- <https://access.redhat.com/errata/RHSA-2026:71115>
- <https://access.redhat.com/errata/RHSA-2026:71177>
- <https://access.redhat.com/errata/RHSA-2026:71179>
- <https://access.redhat.com/security/cve/CVE-2026-84502>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2527096>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-84502) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
