CVE-2026-84718: Use of Less Trusted Source in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
AI Analysis
Technical Summary
The vulnerability exists because the automation-controller in Red Hat Ansible Automation Platform 2, in its default production configuration, trusts the leftmost value of the client-supplied X-Forwarded-For header as the client IP without verifying that the request came from a trusted proxy. This enables an attacker to forge the source IP address recorded in audit and access logs, degrading the integrity of forensic and SIEM attribution. The issue is limited to log integrity and does not provide additional access or disclose information. A robust fix involves using the trusted-proxy shared-secret mechanism to prefer the rightmost trusted entry or selecting the rightmost entry rather than the leftmost. Merely populating PROXY_IP_ALLOWED_LIST does not fully resolve the issue in some deployment scenarios.
Potential Impact
The impact is limited to the integrity of audit and access logs where the source IP address can be spoofed by an attacker. This undermines forensic investigations and SIEM attribution but does not affect confidentiality, availability, or grant any additional privileges or access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor advisory notes that merely setting PROXY_IP_ALLOWED_LIST is insufficient in some deployments. The recommended fix is to use the trusted-proxy shared-secret mechanism to prefer the trusted rightmost X-Forwarded-For entry or to select the rightmost entry rather than the leftmost. Monitor Red Hat's advisory page for updates and apply official fixes when available.
CVE-2026-84718: Use of Less Trusted Source in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
Description
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
CVSS v3.1
Score 4.3medium
Affected software
Red Hat
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists because the automation-controller in Red Hat Ansible Automation Platform 2, in its default production configuration, trusts the leftmost value of the client-supplied X-Forwarded-For header as the client IP without verifying that the request came from a trusted proxy. This enables an attacker to forge the source IP address recorded in audit and access logs, degrading the integrity of forensic and SIEM attribution. The issue is limited to log integrity and does not provide additional access or disclose information. A robust fix involves using the trusted-proxy shared-secret mechanism to prefer the rightmost trusted entry or selecting the rightmost entry rather than the leftmost. Merely populating PROXY_IP_ALLOWED_LIST does not fully resolve the issue in some deployment scenarios.
Potential Impact
The impact is limited to the integrity of audit and access logs where the source IP address can be spoofed by an attacker. This undermines forensic investigations and SIEM attribution but does not affect confidentiality, availability, or grant any additional privileges or access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor advisory notes that merely setting PROXY_IP_ALLOWED_LIST is insufficient in some deployments. The recommended fix is to use the trusted-proxy shared-secret mechanism to prefer the trusted rightmost X-Forwarded-For entry or to select the rightmost entry rather than the leftmost. Monitor Red Hat's advisory page for updates and apply official fixes when available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-02T01:18:24.873Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-84718","vendor":"Red Hat"}]
Threat ID: 6ab42d09f7a7c541063f0e49
Added to database: 09/23/2026, 19:48:25 UTC
Last enriched: 09/23/2026, 20:05:48 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.