CVE-2018-10874: Red Hat Ansible Engine

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

Affected products

  • Red Hat Ansible Engine: version 2.0 only; version 2.4 only; version 2.5 only; version 2.6 only
  • Red Hat Openstack: version 10 only; version 12 only; version 13 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-07-02. Last modified 2026-06-17.