CVE-2026-84502
Red Hat Ansible Project URL Injection Command Execution
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in Red Hat Ansible Automation Platform's automation controller allows an authenticated user to execute arbitrary commands on the control-plane task pod. This occurs due to improper validation of project URLs, which can be crafted to exploit the git SCM module. Exploitation could lead to cross-tenant com