---
cve: "CVE-2026-84719"
severity: "CRITICAL"
cvss: 9.9
epss: "0.4%"
vendor: "Red Hat"
kev: false
exploited: false
published: "2026-09-23 20:17:18"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-28T10:09:27+02:00"
---

# CVE-2026-84719

> 9.9 CRITICAL

## Beschreibung

A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,
unified_job_template, and credentials of each cloned node and fails to check the instance_groups
(and execution_environment and labels) that were preserved from the original. A user with
organization workflow-admin permission but no role on the referenced instance groups can copy a
workflow, become its administrator, and launch jobs pinned to instance groups they are not
authorized to use — including the control-plane instance group — bypassing the InstanceGroup
use_role boundary and causing attacker-influenced automation to run in the control-plane
execution context.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3555) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.

## Referenzen

- <https://access.redhat.com/errata/RHSA-2026:71113>
- <https://access.redhat.com/errata/RHSA-2026:71114>
- <https://access.redhat.com/errata/RHSA-2026:71115>
- <https://access.redhat.com/errata/RHSA-2026:71177>
- <https://access.redhat.com/errata/RHSA-2026:71179>
- <https://access.redhat.com/security/cve/CVE-2026-84719>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2527213>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-84719) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
