Skip to main content

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. (CVE-2026-84721)

0
Medium
Published: 09/23/2026 (09/23/2026, 21:30:58 UTC)
Source: GCVE Database

Description

A server-side request forgery (SSRF) vulnerability exists in the Ansible Automation Platform automation-controller email notification backend. This flaw allows an authenticated user with notification-admin permission to specify arbitrary SMTP hosts and ports in email notification templates without validation, enabling internal network port scanning and potential credential exposure. The vulnerability affects the controller's ability to restrict connections to internal, loopback, link-local, or reserved addresses. When exploited, it can leak connection results and, if SMTP credentials are stored in shared templates, may lead to credential exfiltration.

CVSS v3.1

Score 6.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 06:56:44 UTC

Technical Analysis

CVE-2026-84721 is an SSRF vulnerability in the Ansible Automation Platform automation-controller email notification backend. The backend uses user-supplied SMTP host and port values directly without validating whether the target is internal or reserved. An authenticated user with organization notification-admin permission can create or modify email notification templates to point to arbitrary internal addresses and trigger test notifications. This causes the controller task process to open raw TCP connections to those addresses, reflecting connection errors back through notification records. This behavior provides a three-state internal port scanning oracle (open, closed, filtered) over the control-plane cluster network, including the in-cluster Kubernetes API. Additionally, if a shared organization template stores an SMTP password, redirecting the host can cause that credential to be sent to an attacker-controlled server. The vulnerability is due to missing validation of connect targets in the email backend, unlike other notification backends which have been hardened. The correct fix involves validating and rejecting private, loopback, link-local, and reserved destinations for all notification backends. Red Hat notes that this validation currently exists only on the 2.7 branch and should be applied broadly.

Potential Impact

An authenticated user with notification-admin permissions can perform internal network port scanning via the automation-controller, potentially mapping internal services including the Kubernetes API. This SSRF flaw can also lead to the exfiltration of stored SMTP credentials if shared templates with passwords are redirected to attacker-controlled servers. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 score is 6.4 (medium severity) with network attack vector, low complexity, low privileges required, no user interaction, and scope changed.

Mitigation Recommendations

Red Hat has identified this vulnerability and notes that the correct fix is to validate SMTP host and port targets for all notification backends, rejecting internal, loopback, link-local, and reserved addresses. This validation currently exists only on the 2.7 branch of the automation-controller. Users should monitor Red Hat advisories for official patches or updates that implement this validation across all supported versions. Until a fix is available, restrict notification-admin permissions to trusted users and avoid storing SMTP credentials in shared templates. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-pm79-7whg-hpfr
Osv Schema Version
1.4.0
Aliases
["CVE-2026-84721"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab4be87f7a7c54106f0df13

Added to database: 09/24/2026, 06:09:11 UTC

Last enriched: 09/24/2026, 06:56:44 UTC

Last updated: 09/24/2026, 08:47:33 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses