A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. (CVE-2026-84721)
A server-side request forgery (SSRF) vulnerability exists in the Ansible Automation Platform automation-controller email notification backend. This flaw allows an authenticated user with notification-admin permission to specify arbitrary SMTP hosts and ports in email notification templates without validation, enabling internal network port scanning and potential credential exposure. The vulnerability affects the controller's ability to restrict connections to internal, loopback, link-local, or reserved addresses. When exploited, it can leak connection results and, if SMTP credentials are stored in shared templates, may lead to credential exfiltration.
AI Analysis
Technical Summary
CVE-2026-84721 is an SSRF vulnerability in the Ansible Automation Platform automation-controller email notification backend. The backend uses user-supplied SMTP host and port values directly without validating whether the target is internal or reserved. An authenticated user with organization notification-admin permission can create or modify email notification templates to point to arbitrary internal addresses and trigger test notifications. This causes the controller task process to open raw TCP connections to those addresses, reflecting connection errors back through notification records. This behavior provides a three-state internal port scanning oracle (open, closed, filtered) over the control-plane cluster network, including the in-cluster Kubernetes API. Additionally, if a shared organization template stores an SMTP password, redirecting the host can cause that credential to be sent to an attacker-controlled server. The vulnerability is due to missing validation of connect targets in the email backend, unlike other notification backends which have been hardened. The correct fix involves validating and rejecting private, loopback, link-local, and reserved destinations for all notification backends. Red Hat notes that this validation currently exists only on the 2.7 branch and should be applied broadly.
Potential Impact
An authenticated user with notification-admin permissions can perform internal network port scanning via the automation-controller, potentially mapping internal services including the Kubernetes API. This SSRF flaw can also lead to the exfiltration of stored SMTP credentials if shared templates with passwords are redirected to attacker-controlled servers. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 score is 6.4 (medium severity) with network attack vector, low complexity, low privileges required, no user interaction, and scope changed.
Mitigation Recommendations
Red Hat has identified this vulnerability and notes that the correct fix is to validate SMTP host and port targets for all notification backends, rejecting internal, loopback, link-local, and reserved addresses. This validation currently exists only on the 2.7 branch of the automation-controller. Users should monitor Red Hat advisories for official patches or updates that implement this validation across all supported versions. Until a fix is available, restrict notification-admin permissions to trusted users and avoid storing SMTP credentials in shared templates. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.
A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. (CVE-2026-84721)
Description
A server-side request forgery (SSRF) vulnerability exists in the Ansible Automation Platform automation-controller email notification backend. This flaw allows an authenticated user with notification-admin permission to specify arbitrary SMTP hosts and ports in email notification templates without validation, enabling internal network port scanning and potential credential exposure. The vulnerability affects the controller's ability to restrict connections to internal, loopback, link-local, or reserved addresses. When exploited, it can leak connection results and, if SMTP credentials are stored in shared templates, may lead to credential exfiltration.
CVSS v3.1
Score 6.4medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84721 is an SSRF vulnerability in the Ansible Automation Platform automation-controller email notification backend. The backend uses user-supplied SMTP host and port values directly without validating whether the target is internal or reserved. An authenticated user with organization notification-admin permission can create or modify email notification templates to point to arbitrary internal addresses and trigger test notifications. This causes the controller task process to open raw TCP connections to those addresses, reflecting connection errors back through notification records. This behavior provides a three-state internal port scanning oracle (open, closed, filtered) over the control-plane cluster network, including the in-cluster Kubernetes API. Additionally, if a shared organization template stores an SMTP password, redirecting the host can cause that credential to be sent to an attacker-controlled server. The vulnerability is due to missing validation of connect targets in the email backend, unlike other notification backends which have been hardened. The correct fix involves validating and rejecting private, loopback, link-local, and reserved destinations for all notification backends. Red Hat notes that this validation currently exists only on the 2.7 branch and should be applied broadly.
Potential Impact
An authenticated user with notification-admin permissions can perform internal network port scanning via the automation-controller, potentially mapping internal services including the Kubernetes API. This SSRF flaw can also lead to the exfiltration of stored SMTP credentials if shared templates with passwords are redirected to attacker-controlled servers. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 score is 6.4 (medium severity) with network attack vector, low complexity, low privileges required, no user interaction, and scope changed.
Mitigation Recommendations
Red Hat has identified this vulnerability and notes that the correct fix is to validate SMTP host and port targets for all notification backends, rejecting internal, loopback, link-local, and reserved addresses. This validation currently exists only on the 2.7 branch of the automation-controller. Users should monitor Red Hat advisories for official patches or updates that implement this validation across all supported versions. Until a fix is available, restrict notification-admin permissions to trusted users and avoid storing SMTP credentials in shared templates. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pm79-7whg-hpfr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-84721"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be87f7a7c54106f0df13
Added to database: 09/24/2026, 06:09:11 UTC
Last enriched: 09/24/2026, 06:56:44 UTC
Last updated: 09/24/2026, 08:47:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.