A flaw was found in Red Hat Ansible Automation Platform's automation- controller. (CVE-2026-84486)
A vulnerability in Red Hat Ansible Automation Platform's automation-controller allows unauthenticated remote attackers to invoke debug endpoints that acquire a cluster-wide scheduler advisory lock. This causes legitimate scheduler runs to be skipped, stalling job dispatch for all tenants and consuming controller web workers. Additionally, the debug root view discloses the list of debug endpoints to unauthenticated users.
AI Analysis
Technical Summary
CVE-2026-84486 is a vulnerability in Red Hat Ansible Automation Platform's automation-controller where four debug views that trigger internal schedulers are accessible to any user, including unauthenticated clients. These debug endpoints are routed in production builds without gating on the debug setting. An attacker can repeatedly invoke these endpoints to acquire the cluster-wide scheduler advisory lock, causing legitimate scheduler runs to be skipped and stalling job dispatch cluster-wide while consuming controller web workers. The debug root view also discloses the list of debug endpoints to unauthenticated callers.
Potential Impact
An unauthenticated remote attacker can cause denial of service by stalling job dispatch for all tenants in the Ansible Automation Platform cluster. The attacker achieves this by acquiring a scheduler advisory lock that prevents legitimate scheduler runs from proceeding. Additionally, sensitive information about debug endpoints is disclosed to unauthenticated users, which may aid further attacks.
Mitigation Recommendations
An official security update is available from Red Hat as detailed in RHSA-2026:71113. Users should apply the update to Red Hat Ansible Automation Platform 2.6 to remediate this vulnerability. No additional mitigation is required once the update is applied.
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. (CVE-2026-84486)
Description
A vulnerability in Red Hat Ansible Automation Platform's automation-controller allows unauthenticated remote attackers to invoke debug endpoints that acquire a cluster-wide scheduler advisory lock. This causes legitimate scheduler runs to be skipped, stalling job dispatch for all tenants and consuming controller web workers. Additionally, the debug root view discloses the list of debug endpoints to unauthenticated users.
CVSS v3.1
Score 8.2high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84486 is a vulnerability in Red Hat Ansible Automation Platform's automation-controller where four debug views that trigger internal schedulers are accessible to any user, including unauthenticated clients. These debug endpoints are routed in production builds without gating on the debug setting. An attacker can repeatedly invoke these endpoints to acquire the cluster-wide scheduler advisory lock, causing legitimate scheduler runs to be skipped and stalling job dispatch cluster-wide while consuming controller web workers. The debug root view also discloses the list of debug endpoints to unauthenticated callers.
Potential Impact
An unauthenticated remote attacker can cause denial of service by stalling job dispatch for all tenants in the Ansible Automation Platform cluster. The attacker achieves this by acquiring a scheduler advisory lock that prevents legitimate scheduler runs from proceeding. Additionally, sensitive information about debug endpoints is disclosed to unauthenticated users, which may aid further attacks.
Mitigation Recommendations
An official security update is available from Red Hat as detailed in RHSA-2026:71113. Users should apply the update to Red Hat Ansible Automation Platform 2.6 to remediate this vulnerability. No additional mitigation is required once the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jr99-3x99-6q34
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-84486"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6ab4be21f7a7c54106eee6f2
Added to database: 09/24/2026, 06:07:29 UTC
Last enriched: 09/24/2026, 06:19:19 UTC
Last updated: 09/24/2026, 14:47:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.