External risk intelligence

Ansible Automation Platform Workflow Copy Instance Group Privilege Escalation.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-84719

Ansible Automation Platform is commonly deployed as a centralized, web-based management and orchestration platform. These interfaces are frequently accessed via a network, often serving as a gateway for automation tasks across an organization's infrastructure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Ansible Automation Platform that could allow unauthorized access to sensitive environments. This flaw arises when copying workflow templates, where certain security checks are bypassed, potentially enabling users to execute automation in contexts they shouldn't access. This could lead to unintended or malicious operations within critical infrastructure.

  • Flaw allows unauthorized automation execution.
  • Matters for controlling sensitive environments.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with specific administrative permissions within the Ansible Automation Platform can exploit a flaw during the copying of workflow job templates. By copying a template, the attacker can gain administrative control over the copied workflow and then intentionally pin its jobs to instance groups they would normally be restricted from accessing, including the control-plane. This allows them to execute automation with elevated privileges in the control-plane's execution context.

  • Entry condition: Organization workflow-admin permission.
  • Trigger point: Copying a workflow job template.
  • Resulting risk: Control-plane execution context bypass.

Live Threat

Current exploitation, exposure, and threat context

A flaw in Ansible Automation Platform's workflow copying mechanism could allow a user with workflow administrative privileges to gain unauthorized control over jobs. When a workflow is copied, certain configurations like instance groups and execution environments are preserved, but the associated permissions are not properly re-validated. This could enable an attacker to designate specific, restricted instance groups for job execution, potentially including the control-plane, leading to unintended or malicious automation actions within that context.

  • Unsanctioned job execution on sensitive instance groups.
  • Workflow copy bypasses instance group permission checks.
  • Attacker-influenced automation runs in restricted contexts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Ansible Automation Platform's automation-controller impacts organizations utilizing workflow job templates. The flaw allows users with specific administrative roles to bypass instance group permissions, potentially leading to unauthorized automation execution within sensitive environments, including the control plane. Platform or infrastructure teams are likely responsible for managing Ansible, with security teams needing to assess exposure. The initial step should involve identifying all instances of the affected platform, confirming their network reachability and business criticality, and then identifying the specific accountable owners before planning remediation.

  • Platform/Infrastructure teams should own the issue.
  • Verify instance group access controls.
  • Plan remediation based on risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Ansible Automation Platform automation-controller?

It is the centralized management component of the Ansible Automation Platform. Organizations use it to orchestrate and run automated tasks across their IT infrastructure through a web-based interface, which serves as the core engine for scheduling, executing, and controlling automation workflows.

What weakness causes CVE-2026-84719?

This CVE involves a missing authorization check, categorized as CWE-862. When a user copies a workflow template, the system fails to verify if the user has permission to access the instance groups preserved from the original workflow. This allows users to assign jobs to restricted resources they were never authorized to manage.

How can an attacker trigger this vulnerability?

An attacker needs existing organization workflow-admin permissions to initiate the copy process for a workflow job template. The flaw is not triggered by standard, read-only access or by running existing, unmodified workflows; it specifically occurs when the workflow is duplicated and the unauthorized instance group assignment takes effect.

Is my system at risk if it is not internet-facing?

Halo Surface Signal indicates that because this platform is typically a centralized web-based management tool, it is often accessible over a network. Even if your installation is internal, users with the required organizational role can exploit this flaw to execute automation in restricted contexts, including the control plane.

What should I do first to address this issue?

Start by identifying all deployed instances of the automation-controller within your environment. Work with your platform or infrastructure teams to confirm the current permission settings for your workflow templates and instance groups, then prioritize updates provided by the vendor to remediate the underlying authorization logic.

References