CVE-2026-84718: Red Hat Ansible Automation Platform 2.5 For Rhel 8
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.33-1.el8ap (fixed in 0:4.6.33-1.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.33-1.el9ap (fixed in 0:4.6.33-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1789673739 (fixed in 1789673739)
- Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.17-1.el9ap (fixed in 0:4.7.17-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.7: before 1789580684 (fixed in 1789580684)
Published 2026-09-23. Last modified 2026-09-24.