Skip to main content
EPSS 0.4%top 64%

Ansible jailexec: Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) (CVE-2026-55074)

0
High
Published: 09/21/2026 (09/21/2026, 14:24:55 UTC)
Source: GCVE Database
Product: ansible-jailexec

Description

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

PyPIghsa
ansible-jailexec
Affected versions
<2.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 22:15:33 UTC

Technical Analysis

The Ansible FreeBSD Jail Connection Plugin (jailexec) up to version 1.3.0 has a vulnerability (CVE-2026-55074) in its put_file method. When transferring files into a FreeBSD jail, the plugin resolves the destination path on the host and executes mkdir -p and mv commands as root on the host. These commands follow symbolic links, so if an attacker can place a symlink inside the jail at or above the transfer destination, the root-privileged mv on the host will follow it, allowing arbitrary root-owned writes outside the jail. This enables a full jail escape and potential host compromise. The vulnerability requires that the operator runs a task using put_file and that the attacker can create symlinks inside the jail before the transfer. The issue is fixed in version 2.0.0.

Potential Impact

An attacker with the ability to create symbolic links inside a FreeBSD jail can cause the Ansible jailexec plugin to perform arbitrary root-owned writes on the host system outside the jail. This can lead to full jail escape and host compromise, including modification of critical files such as cron jobs, startup scripts, or authorized_keys, potentially allowing persistent and privileged access to the host.

Mitigation Recommendations

This vulnerability is fixed in Ansible jailexec version 2.0.0. Operators should upgrade to version 2.0.0 or later to remediate this issue. Until upgraded, avoid running put_file tasks against jails where untrusted users can create symbolic links in the target directories. Patch status is confirmed as a fix available in version 2.0.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-cxgv-hp74-jj7r
Osv Schema Version
1.4.0
Aliases
["CVE-2026-55074"]
Ecosystems
["PyPI"]
Database Specific Severity
HIGH
Cvss Version
4.0

Threat ID: 6a7e034ebf8831d5398f6be5

Added to database: 08/13/2026, 17:47:58 UTC

Last enriched: 09/21/2026, 22:15:33 UTC

Last updated: 09/26/2026, 04:01:02 UTC

Views: 43

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses