External risk intelligence

Red Hat Ansible Automation Platform Controller Secret Exposure and Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-84474

The vulnerability affects the automation-controller component of Red Hat Ansible Automation Platform, which is typically deployed as a centralized, web-based management service. Because this platform serves as an API and interface for managing infrastructure and is often accessible to authorized users across networks, it is commonly exposed as an edge-service or administrative interface.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Red Hat Ansible Automation Platform's automation controller. This flaw allows an attacker with minimal privileges to potentially execute arbitrary code on managed systems by exploiting a credential exposure and manipulating network headers. The main concern is confirming relevance and exposure given the platform's role in managing critical infrastructure.

  • A secret can be read by low-privilege users.
  • Attackers can gain remote control of systems.
  • Assess exposure of Ansible Automation Platform.

Attack Path

How an attacker could exploit the issue

An attacker with read-only access to job templates can uncover a secret used for provisioning callbacks. By then manipulating the gateway's header, they can trick the system into believing the request originates from a managed host. This allows them to launch jobs against arbitrary hosts, leading to unauthorized execution of commands.

  • Requires minimal user access.
  • Spoofed header triggers callback.
  • Leads to code execution on hosts.

Live Threat

Current exploitation, exposure, and threat context

A flaw in Red Hat Ansible Automation Platform's automation-controller could allow a minimally privileged user to access a sensitive secret. When the controller is deployed behind the AAP gateway with an empty proxy allow-list, an attacker could potentially read this secret and then spoof the X-Forwarded-For header to impersonate a host within the job template's inventory. This could lead to the attacker launching job templates against arbitrary managed hosts using the job template's credentials, potentially resulting in privilege escalation and remote code execution on those hosts.

  • Secret and job template credentials at risk.
  • Attacker spoofs X-Forwarded-For header.
  • Privilege escalation and code execution possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability impacts Red Hat Ansible Automation Platform's automation-controller. Responsibility for remediation likely falls to the platform or infrastructure teams, in coordination with security teams. The first practical step is to identify all instances of the affected platform, determine their exposure and business criticality, and locate the accountable owner to plan mitigation.

  • Platform or infrastructure teams own the issue.
  • Verify affected controller accessibility and criticality.
  • Plan remediation based on exposure and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Red Hat Ansible Automation Platform controller?

It is the central management engine of the platform, providing a web-based interface and API to automate IT infrastructure tasks. It orchestrates how configurations are pushed to managed systems and oversees the execution of automated playbooks across an organization's environment.

What does CWE-807 mean for CVE-2026-84474?

CWE-807 refers to reliance on untrusted inputs in a security decision. In this case, the automation controller incorrectly trusts a client-supplied X-Forwarded-For header to verify host identity. This vulnerability allows an attacker to manipulate network data to bypass intended access controls and trigger unauthorized actions.

How can an attacker trigger this vulnerability?

An attacker needs read access to a job template to steal the provisioning-callback secret. They must then send a request with a spoofed X-Forwarded-For header to the controller. This attack does not trigger if the controller is not deployed behind an AAP gateway with an empty proxy allow-list, as the gateway configuration is key to the flaw.

Is my instance relevant according to Halo Surface Signal?

Halo Surface Signal identifies that this platform is typically deployed as a centralized management service, often acting as an edge-service or administrative interface. Because it is designed to be accessible to users across networks, instances that are network-reachable are considered more likely to be relevant for review.

Do I need to patch CVE-2026-84474 immediately?

The first step is to locate all instances of the automation controller within your infrastructure to assess their business criticality and network exposure. Once identified, work with the platform or infrastructure teams to coordinate updates, as this is a critical issue that permits unauthorized command execution on your managed hosts.

References