CVE-2026-84724: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments — including Python's path option — into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.
AI Analysis
Technical Summary
The vulnerability in Red Hat Ansible Automation Platform 2's automation-controller system-job subsystem involves improper neutralization of argument delimiters (CWE-88). The system-job template launch endpoint accepts a 'days' variable without integer validation, and the dispatcher concatenates command arguments into a single string with spaces, which the job runner then re-splits. This allows spaces in the 'days' value to inject additional command-line arguments. Since system jobs run in-process on the control node without container isolation, an authenticated superuser can inject arbitrary arguments, including Python path options, into the awx-manage process. This grants control over the process argument vector and the first entry of the Python module search path. However, full remote code execution requires an additional import gadget not present in current management commands. The recommended fix involves proper quoting of runner arguments, validation of extra_vars, and coercion of numeric options.
Potential Impact
An authenticated user with superuser privileges can inject arbitrary command-line arguments into the awx-manage process on the control node, potentially altering the process's module search path and behavior. This could lead to unauthorized code execution if combined with an additional import gadget, which is currently not present. The impact includes potential confidentiality, integrity, and availability issues, but full remote code execution has not been demonstrated.
Mitigation Recommendations
Red Hat has identified the flaw and recommends applying the fix that includes proper quoting of runner arguments using shlex-safe methods, validating the 'extra_vars' at launch time through existing validators, and coercing numeric options with int(). Users should monitor Red Hat advisories for the official patch release and apply it when available. Until then, exploitation requires superuser privileges, and no known mitigations are explicitly stated beyond applying the forthcoming fix.
CVE-2026-84724: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
Description
An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments — including Python's path option — into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.
CVSS v3.1
Score 6.6medium
Affected software
Red Hat
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Red Hat Ansible Automation Platform 2's automation-controller system-job subsystem involves improper neutralization of argument delimiters (CWE-88). The system-job template launch endpoint accepts a 'days' variable without integer validation, and the dispatcher concatenates command arguments into a single string with spaces, which the job runner then re-splits. This allows spaces in the 'days' value to inject additional command-line arguments. Since system jobs run in-process on the control node without container isolation, an authenticated superuser can inject arbitrary arguments, including Python path options, into the awx-manage process. This grants control over the process argument vector and the first entry of the Python module search path. However, full remote code execution requires an additional import gadget not present in current management commands. The recommended fix involves proper quoting of runner arguments, validation of extra_vars, and coercion of numeric options.
Potential Impact
An authenticated user with superuser privileges can inject arbitrary command-line arguments into the awx-manage process on the control node, potentially altering the process's module search path and behavior. This could lead to unauthorized code execution if combined with an additional import gadget, which is currently not present. The impact includes potential confidentiality, integrity, and availability issues, but full remote code execution has not been demonstrated.
Mitigation Recommendations
Red Hat has identified the flaw and recommends applying the fix that includes proper quoting of runner arguments using shlex-safe methods, validating the 'extra_vars' at launch time through existing validators, and coercing numeric options with int(). Users should monitor Red Hat advisories for the official patch release and apply it when available. Until then, exploitation requires superuser privileges, and no known mitigations are explicitly stated beyond applying the forthcoming fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-02T01:55:24.865Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-84724","vendor":"Red Hat"}]
Threat ID: 6ab42d0af7a7c541063f0e4f
Added to database: 09/23/2026, 19:48:26 UTC
Last enriched: 09/23/2026, 20:05:13 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.