{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ared_hatansible_automation_platform/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:ansible_automation_platform:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-84499"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ansible Automation Platform (automation-controller)"],"_cs_severities":["high"],"_cs_tags":["credential-theft","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-84499 is a security vulnerability in the Red Hat Ansible Automation Platform automation-controller where sensitive survey data, specifically password-type fields, are improperly handled during validation. These fields are typically stored encrypted and intended to be write-only, masking their value when viewed via the UI or API. However, when a user with the JobTemplate Admin role modifies a schedule or workflow job template node to use a stricter survey length specification, the automation-controller triggers a revalidation process. During this process, the application inadvertently decrypts the stored password and echoes the plaintext value directly into the HTTP response body as part of a minimum/maximum length validation error message. This allows a malicious or compromised administrative user to recover plaintext credentials belonging to higher-privileged users, leading to potential privilege escalation or lateral movement across the infrastructure managed by Ansible.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the exposure of plaintext credentials stored within Ansible surveys. This impacts organizations using the platform for automated secret management or infrastructure orchestration, potentially leading to unauthorized access to downstream systems and administrative takeover of the automation-controller environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Red Hat Ansible Automation Platform to the patched version once released by Red Hat to resolve CVE-2026-84499.\u003c/li\u003e\n\u003cli\u003eAudit logs for the automation-controller for frequent or suspicious modifications to job template survey specifications by low-privileged administrators.\u003c/li\u003e\n\u003cli\u003eRestrict the 'JobTemplate Admin' role in Ansible environments to highly trusted personnel until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T20:44:30Z","date_published":"2026-09-23T20:44:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ansible-controller-vuln/","summary":"A vulnerability in Red Hat Ansible Automation Platform's automation-controller allows a low-privileged JobTemplate Admin to exfiltrate plaintext passwords from survey questions via error message injection.","title":"Credential Exposure in Red Hat Ansible Automation Platform via CVE-2026-84499","url":"https://feed.craftedsignal.io/briefs/2026-09-ansible-controller-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:red_hat:ansible_automation_platform:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}