External risk intelligence

Red Hat Ansible Project URL Injection Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-84502

The vulnerability exists in the Ansible Automation Platform automation-controller, which is often deployed as a management service. While typically accessed by authorized internal users or administrators, it is a web-based service that may be exposed to the internet in some deployments to support remote automation workflows, making network-based reachability possible.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Red Hat Ansible Automation Platform's automation controller that could allow unauthorized command execution. Specifically, a flaw in how project URLs are handled enables an attacker with project modification permissions to run arbitrary commands on the control-plane task pod. This could lead to broader compromise within the cluster, impacting multiple tenants. The primary concern is to confirm if your Ansible Automation Platform is affected and to what extent.

  • Flaw allows attackers to run commands on the Ansible controller.
  • Remote code execution can lead to cross-tenant compromise.
  • Assess relevance and exposure for Ansible Automation Platform.

Attack Path

How an attacker could exploit the issue

An attacker with the ability to create or modify projects could exploit this vulnerability. By crafting a malicious project URL, an attacker can trick the system into executing arbitrary commands on the control-plane task pod. This leads to potential command execution, data compromise, and unauthorized lateral movement within the cluster.

  • Network access required; authenticated user.
  • Malicious project URL triggers command execution.
  • Arbitrary code execution and lateral movement.

Live Threat

Current exploitation, exposure, and threat context

When supported, a user with project creation privileges could execute arbitrary commands on the control-plane task pod by providing a specially crafted git project URL. This could lead to cross-tenant compromise and lateral movement within the cluster.

  • Control-plane task pod command execution.
  • Specially crafted project URL input.
  • In-cluster lateral movement.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Ansible Automation Platform team is likely responsible for this issue, with support from infrastructure or platform teams for deployment. The first practical step is to identify all instances of the automation controller, assess their exposure and criticality, and locate the accountable owner for each. Remediation planning should then be prioritized based on these findings.

  • Ansible Automation Platform team owns the issue.
  • Verify controller instance exposure and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Red Hat Ansible Automation Platform's automation-controller?

It is a centralized management hub used to orchestrate IT infrastructure, such as cloud provisioning, configuration management, and application deployment. It serves as the primary engine for executing automated workflows across enterprise environments, managing task execution pods that interface with various code repositories and systems.

How does CVE-2026-84502 work as a vulnerability?

This flaw is an example of CWE-88: Argument Injection. The system fails to sanitize input in the project SCM URL field, allowing a user to inject command-line flags. By starting a URL with a dash, an attacker can trick the underlying git software into executing unintended shell commands instead of simply connecting to a repository.

Can any user trigger this command execution?

No. Triggering the vulnerability requires the attacker to have existing, legitimate permissions to create or modify project configurations within the platform. Simply interacting with the web interface or viewing existing projects does not initiate the flaw; it specifically requires the ability to input a malicious URL string that the controller processes.

Is my deployment at risk according to Halo Surface Signal?

Halo Surface Signal labels this as a possible risk. While the automation-controller is typically used by internal teams, its role as a management service means some organizations expose it to the internet to support remote workflows. If your instance is internet-facing, the potential for unauthorized network-based access increases your risk profile.

How should I respond to this threat?

Begin by auditing your infrastructure to locate all instances of the automation-controller. Once identified, evaluate which instances are reachable over the network and verify who has project modification privileges. Prioritize securing these controllers and coordinate with your platform teams to plan and apply the necessary vendor-provided updates.

References