Ansible jailexec: Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) (CVE-2026-55074)
Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.
AI Analysis
Technical Summary
The Ansible FreeBSD Jail Connection Plugin (jailexec) up to version 1.3.0 has a vulnerability (CVE-2026-55074) in its put_file method. When transferring files into a FreeBSD jail, the plugin resolves the destination path on the host and executes mkdir -p and mv commands as root on the host. These commands follow symbolic links, so if an attacker can place a symlink inside the jail at or above the transfer destination, the root-privileged mv on the host will follow it, allowing arbitrary root-owned writes outside the jail. This enables a full jail escape and potential host compromise. The vulnerability requires that the operator runs a task using put_file and that the attacker can create symlinks inside the jail before the transfer. The issue is fixed in version 2.0.0.
Potential Impact
An attacker with the ability to create symbolic links inside a FreeBSD jail can cause the Ansible jailexec plugin to perform arbitrary root-owned writes on the host system outside the jail. This can lead to full jail escape and host compromise, including modification of critical files such as cron jobs, startup scripts, or authorized_keys, potentially allowing persistent and privileged access to the host.
Mitigation Recommendations
This vulnerability is fixed in Ansible jailexec version 2.0.0. Operators should upgrade to version 2.0.0 or later to remediate this issue. Until upgraded, avoid running put_file tasks against jails where untrusted users can create symbolic links in the target directories. Patch status is confirmed as a fix available in version 2.0.0.
Ansible jailexec: Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) (CVE-2026-55074)
Description
Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Ansible FreeBSD Jail Connection Plugin (jailexec) up to version 1.3.0 has a vulnerability (CVE-2026-55074) in its put_file method. When transferring files into a FreeBSD jail, the plugin resolves the destination path on the host and executes mkdir -p and mv commands as root on the host. These commands follow symbolic links, so if an attacker can place a symlink inside the jail at or above the transfer destination, the root-privileged mv on the host will follow it, allowing arbitrary root-owned writes outside the jail. This enables a full jail escape and potential host compromise. The vulnerability requires that the operator runs a task using put_file and that the attacker can create symlinks inside the jail before the transfer. The issue is fixed in version 2.0.0.
Potential Impact
An attacker with the ability to create symbolic links inside a FreeBSD jail can cause the Ansible jailexec plugin to perform arbitrary root-owned writes on the host system outside the jail. This can lead to full jail escape and host compromise, including modification of critical files such as cron jobs, startup scripts, or authorized_keys, potentially allowing persistent and privileged access to the host.
Mitigation Recommendations
This vulnerability is fixed in Ansible jailexec version 2.0.0. Operators should upgrade to version 2.0.0 or later to remediate this issue. Until upgraded, avoid running put_file tasks against jails where untrusted users can create symbolic links in the target directories. Patch status is confirmed as a fix available in version 2.0.0.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cxgv-hp74-jj7r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55074"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7e034ebf8831d5398f6be5
Added to database: 08/13/2026, 17:47:58 UTC
Last enriched: 09/21/2026, 22:15:33 UTC
Last updated: 09/26/2026, 04:01:02 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.