Skip to main content
EPSS 0.2%top 87%

CVE-2026-11332: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8

0
High
VulnerabilityCVE-2026-11332cvecve-2026-11332
Published: 06/05/2026 (06/05/2026, 08:21:43 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2.5 for RHEL 8

Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 8

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.6 for RHEL 10

Red Hat

Red Hat Ansible Automation Platform 2.6 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.7 for RHEL 10

Red Hat

Red Hat Ansible Automation Platform 2.7 for RHEL 9

Red Hat

Red Hat Enterprise Linux 10

Red Hat

Red Hat Enterprise Linux 10.0 Extended Update Support

Red Hat

Red Hat Enterprise Linux 8

Red Hat

Red Hat Enterprise Linux 9

Red Hat

Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Red Hat

Red Hat Enterprise Linux 9.6 Extended Update Support

Red Hat

Red Hat Satellite 6.17 for RHEL 9

Red Hat

Red Hat Satellite 6.18 for RHEL 9

Red Hat

Red Hat Satellite 6.18 for RHEL 9

Red Hat

Red Hat Satellite 6.18 for RHEL 9

Red Hat

Red Hat Satellite 6.19 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.5

Red Hat

Red Hat Ansible Automation Platform 2.5

Red Hat

Red Hat Ansible Automation Platform 2.5

Red Hat

Red Hat Ansible Automation Platform 2.5

Red Hat

Red Hat Ansible Automation Platform 2.5

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.7

Red Hat

Red Hat Ansible Automation Platform 2.7

Red Hat

Red Hat Ansible Automation Platform 2.7

Red Hat

Red Hat Ansible Automation Platform 2.7

Red Hat

Red Hat Discovery 2

Red Hat

Migration Toolkit for Applications 8

Red Hat

Migration Toolkit for Virtualization

Red Hat

OpenShift Service Mesh 3

Red Hat

Red Hat Advanced Cluster Management for Kubernetes 2

Red Hat

Red Hat Ansible Automation Platform 2

Red Hat

Red Hat Ansible Automation Platform 2

Red Hat

Red Hat Ansible Automation Platform Ansible Core 2

Red Hat

Red Hat OpenShift Container Platform 4

Red Hat

Self-service automation portal 2

Red Hat

Service Telemetry Framework 1.5

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 17:20:43 UTC

Technical Analysis

The vulnerability CVE-2026-11332 exists in ansible-core, specifically in the ansible-galaxy role install command which processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This injection can lead to arbitrary code execution on the system of any user who installs the malicious role via ansible-galaxy role install. The vulnerability is classified under CWE-88 (Improper Neutralization of Argument Delimiters in a Command). The affected product is Red Hat Ansible Automation Platform 2.5 for RHEL 8, specifically versions >=2.5.0 and <2.6.0. Red Hat has issued security advisories (RHSA-2026:42078 and RHSA-2026:42079) that include fixes for this vulnerability in version 2.6 and later. The CVSS v3.1 score is 7.8, indicating high severity, with attack vector local, low attack complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability.

Potential Impact

Successful exploitation of this vulnerability allows a malicious role author to execute arbitrary code on the machine of a user who installs the crafted role. This can compromise the confidentiality, integrity, and availability of the affected system. The vulnerability requires local access and user interaction (installing the malicious role) but does not require privileges. The impact is rated high due to the potential for full system compromise.

Mitigation Recommendations

Red Hat has released official patches for this vulnerability in Red Hat Ansible Automation Platform version 2.6 and later. Users running affected versions (>=2.5.0 <2.6.0) should upgrade to the fixed versions as documented in Red Hat advisories RHSA-2026:42078 and RHSA-2026:42079. Applying these updates will remediate the vulnerability. No additional mitigation steps are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-06-05T07:58:25.632Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-11332","vendor":"Red Hat"}]

Threat ID: 6a22946de29bf47b5052568e

Added to database: 06/05/2026, 09:18:37 UTC

Last enriched: 08/11/2026, 17:20:43 UTC

Last updated: 09/14/2026, 22:32:16 UTC

Views: 189

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses