A flaw was found in the automation-controller API. (CVE-2026-84712)
CVE-2026-84712 is a vulnerability in the automation-controller API where an unauthenticated health-check endpoint (/api/v2/ping/) over-serializes role-based access control (RBAC) gated automation-mesh data. This exposure reveals detailed instance inventory information including node hostnames, types, UUIDs, heartbeats, capacities, versions, instance-group names and memberships, deployment install UUID, and the active control node. The flaw impacts confidentiality by allowing remote unauthenticated attackers to map the control plane and fingerprint software versions. It does not expose secrets, credentials, or tenant data.
AI Analysis
Technical Summary
The automation-controller API has an unauthenticated endpoint (/api/v2/ping/) that returns over-serialized RBAC-protected automation-mesh data in its anonymous response. This data includes comprehensive instance inventory details such as node hostnames, types, UUIDs, heartbeats, capacities, exact software versions, instance-group names and memberships, deployment install UUID, and the active control node. The vulnerability allows remote unauthenticated attackers to map the control plane and fingerprint software versions, affecting confidentiality but not exposing secrets, credentials, or tenant data.
Potential Impact
The vulnerability impacts confidentiality by exposing detailed infrastructure and software version information to unauthenticated remote attackers. This information disclosure can facilitate targeted attacks by enabling attackers to map the control plane and identify software versions in use. However, it does not expose sensitive secrets, credentials, or tenant-specific data, limiting the scope of impact to information disclosure only.
Mitigation Recommendations
A security update addressing this vulnerability is available as part of the Red Hat Ansible Automation Platform 2.6 update (RHSA-2026:71113). Users should apply this official fix to remediate the issue. No additional mitigation steps are required beyond applying the vendor-provided patch.
A flaw was found in the automation-controller API. (CVE-2026-84712)
Description
CVE-2026-84712 is a vulnerability in the automation-controller API where an unauthenticated health-check endpoint (/api/v2/ping/) over-serializes role-based access control (RBAC) gated automation-mesh data. This exposure reveals detailed instance inventory information including node hostnames, types, UUIDs, heartbeats, capacities, versions, instance-group names and memberships, deployment install UUID, and the active control node. The flaw impacts confidentiality by allowing remote unauthenticated attackers to map the control plane and fingerprint software versions. It does not expose secrets, credentials, or tenant data.
CVSS v3.1
Score 5.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The automation-controller API has an unauthenticated endpoint (/api/v2/ping/) that returns over-serialized RBAC-protected automation-mesh data in its anonymous response. This data includes comprehensive instance inventory details such as node hostnames, types, UUIDs, heartbeats, capacities, exact software versions, instance-group names and memberships, deployment install UUID, and the active control node. The vulnerability allows remote unauthenticated attackers to map the control plane and fingerprint software versions, affecting confidentiality but not exposing secrets, credentials, or tenant data.
Potential Impact
The vulnerability impacts confidentiality by exposing detailed infrastructure and software version information to unauthenticated remote attackers. This information disclosure can facilitate targeted attacks by enabling attackers to map the control plane and identify software versions in use. However, it does not expose sensitive secrets, credentials, or tenant-specific data, limiting the scope of impact to information disclosure only.
Mitigation Recommendations
A security update addressing this vulnerability is available as part of the Red Hat Ansible Automation Platform 2.6 update (RHSA-2026:71113). Users should apply this official fix to remediate the issue. No additional mitigation steps are required beyond applying the vendor-provided patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cvm2-8wp9-2853
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-84712"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6ab4be23f7a7c54106eee979
Added to database: 09/24/2026, 06:07:31 UTC
Last enriched: 09/24/2026, 06:19:34 UTC
Last updated: 09/25/2026, 02:47:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.