CVE-2026-84719: Red Hat Ansible Automation Platform 2.4 For Rhel 8

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 8: before 0:4.5.36-1.el8ap (fixed in 0:4.5.36-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 9: before 0:4.5.36-1.el9ap (fixed in 0:4.5.36-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.33-1.el8ap (fixed in 0:4.6.33-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.33-1.el9ap (fixed in 0:4.6.33-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1789673739 (fixed in 1789673739)
  • Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.17-1.el9ap (fixed in 0:4.7.17-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1789580684 (fixed in 1789580684)

Published 2026-09-23. Last modified 2026-09-25.