{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aansiblecommunity.general/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ansible:community.general:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-87874"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["community.general"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Ansible"],"content_html":"\u003cp\u003eThe community.general Ansible collection contains a vulnerability in its memcached cache plugin that exposes Ansible controllers to remote code execution. Although the plugin documentation implies records are stored in JSON, it lacks explicit serialization, relying instead on python-memcached. This library defaults to pickling values during write operations and unpickling them upon retrieval. Because memcached instances frequently lack authentication and cache keys are often predictable, an attacker with network access to the memcached server can inject a crafted pickle payload. When the Ansible controller attempts to retrieve a fact from the poisoned cache, the deserialization process triggers arbitrary code execution. This vulnerability is critical in environments where memcached instances are shared or exposed to untrusted network segments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in full remote code execution on the Ansible controller, potentially granting an attacker complete control over the automation environment. This allows for the manipulation of infrastructure, theft of secrets, and horizontal movement within the target network. The impact is significant for organizations relying on Ansible for large-scale configuration management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all Ansible controller configurations to identify usage of the memcached cache plugin.\u003c/li\u003e\n\u003cli\u003eImplement strict network access control lists (ACLs) to ensure that memcached instances are not accessible from unauthorized segments or untrusted hosts.\u003c/li\u003e\n\u003cli\u003eUpgrade the community.general Ansible collection to the latest patched version when available.\u003c/li\u003e\n\u003cli\u003eTransition from unauthenticated memcached instances to configurations that enforce authentication or encryption if the environment allows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T19:01:56Z","date_published":"2026-09-09T19:01:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ansible-pickle-rce/","summary":"An insecure deserialization vulnerability in the community.general Ansible collection's memcached cache plugin allows unauthenticated attackers to achieve remote code execution via pickle payload injection.","title":"Remote Code Execution in Ansible community.general Memcached Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-ansible-pickle-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ansible:community.general:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}