Skip to main content

CVE-2026-84724: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9

0
Medium
VulnerabilityCVE-2026-84724cvecve-2026-84724
Published: 09/23/2026 (09/23/2026, 19:40:42 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2.6 for RHEL 9

Description

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments — including Python's path option — into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.

CVSS v3.1

Score 6.6medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Affected software

Red Hat

Red Hat Ansible Automation Platform 2.6 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 20:05:13 UTC

Technical Analysis

The vulnerability in Red Hat Ansible Automation Platform 2's automation-controller system-job subsystem involves improper neutralization of argument delimiters (CWE-88). The system-job template launch endpoint accepts a 'days' variable without integer validation, and the dispatcher concatenates command arguments into a single string with spaces, which the job runner then re-splits. This allows spaces in the 'days' value to inject additional command-line arguments. Since system jobs run in-process on the control node without container isolation, an authenticated superuser can inject arbitrary arguments, including Python path options, into the awx-manage process. This grants control over the process argument vector and the first entry of the Python module search path. However, full remote code execution requires an additional import gadget not present in current management commands. The recommended fix involves proper quoting of runner arguments, validation of extra_vars, and coercion of numeric options.

Potential Impact

An authenticated user with superuser privileges can inject arbitrary command-line arguments into the awx-manage process on the control node, potentially altering the process's module search path and behavior. This could lead to unauthorized code execution if combined with an additional import gadget, which is currently not present. The impact includes potential confidentiality, integrity, and availability issues, but full remote code execution has not been demonstrated.

Mitigation Recommendations

Red Hat has identified the flaw and recommends applying the fix that includes proper quoting of runner arguments using shlex-safe methods, validating the 'extra_vars' at launch time through existing validators, and coercing numeric options with int(). Users should monitor Red Hat advisories for the official patch release and apply it when available. Until then, exploitation requires superuser privileges, and no known mitigations are explicitly stated beyond applying the forthcoming fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-09-02T01:55:24.865Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-84724","vendor":"Red Hat"}]

Threat ID: 6ab42d0af7a7c541063f0e4f

Added to database: 09/23/2026, 19:48:26 UTC

Last enriched: 09/23/2026, 20:05:13 UTC

Last updated: 09/24/2026, 01:57:04 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses