Red Hat Linux OS and other open source products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Red Hat product.
RSS Feeds for Red Hat security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Red Hat Sorted by Most Security Vulnerabilities since 2018
Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.
Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.
Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop
Recent Red Hat Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:72888 | (RHSA-2026:72888) Moderate: java-21-ibm-semeru-certified-jdk security update | September 28, 2026 |
| RHSA-2026:72832 | (RHSA-2026:72832) Important: kpatch-patch-5_14_0-687_10_1 security update | September 28, 2026 |
| RHSA-2026:72831 | (RHSA-2026:72831) Important: kpatch-patch-6_12_0-211_16_1 and kpatch-patch-6_12_0-211_49_1 security update | September 28, 2026 |
| RHSA-2026:72820 | (RHSA-2026:72820) Important: acl security update | September 28, 2026 |
| RHSA-2026:72819 | (RHSA-2026:72819) Important: acl security update | September 28, 2026 |
| RHSA-2026:72805 | (RHSA-2026:72805) Important: git-lfs security update | September 28, 2026 |
| RHSA-2026:72785 | (RHSA-2026:72785) Important: ruby security update | September 28, 2026 |
| RHSA-2026:72498 | (RHSA-2026:72498) Red Hat Hardened Images RPMs Security Update | September 28, 2026 |
| RHSA-2026:72497 | (RHSA-2026:72497) Red Hat Hardened Images RPMs Security Update | September 28, 2026 |
| RHSA-2026:72750 | (RHSA-2026:72750) Red Hat Hardened Images RPMs Security Update | September 28, 2026 |
By the Year
In 2026 there have been 3746 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1184 security vulnerabilities published. That is, 2562 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3746 | 7.24 |
| 2025 | 1184 | 6.86 |
| 2024 | 1695 | 6.82 |
| 2023 | 1207 | 6.75 |
| 2022 | 1362 | 6.96 |
| 2021 | 1123 | 6.61 |
| 2020 | 664 | 6.39 |
| 2019 | 772 | 6.98 |
| 2018 | 760 | 7.16 |
It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-97029 | Sep 29, 2026 |
Flatpak PID NS Leak: kill(0) Kills Unsandboxed ProcessesFlatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell. |
|
| CVE-2026-97024 | Sep 29, 2026 |
Flatpak Path Traversal Vulnerability Evicts Host Files via App DeploymentA path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root. |
|
| CVE-2026-97027 | Sep 28, 2026 |
Flatpak Vendor-Extension Key Injection in Desktop Entry ExportFlatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit. |
|
| CVE-2026-97026 | Sep 28, 2026 |
Flatpak Temp Dir 0777 Permission (CVE-2026-97026)Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted. |
|
| CVE-2026-97025 | Sep 28, 2026 |
World-Readable OCI Auth Token Exposure in Flatpak System-HelperFlatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not. |
|
| CVE-2026-97023 | Sep 28, 2026 |
Flatpak Export/bin Path Traversal Enables File DeletionA path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root. |
|
| CVE-2026-96740 | Sep 28, 2026 |
Red Hat StreamsHub Console: CR Config Leak Exfiltrates Kafka Auth TokenA flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker. |
|
| CVE-2026-87114 | Sep 28, 2026 |
Red Hat kube-compare Container Ref Path RCE on Operator WorkstationA flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk. |
|
| CVE-2026-86330 | Sep 28, 2026 |
NooBaa set_hostname_internal OS Command Injection (CVE-2026-86330)An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process. |
|
| CVE-2026-96284 | Sep 27, 2026 |
Flatpak System-Helper Symlink Traversal Grants File ReadA malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control. |
|
| CVE-2026-96282 | Sep 27, 2026 |
Flatpak Extension Host FS Enumeration & Unvalidated Metadata MountA malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox. |
|
| CVE-2026-96283 | Sep 27, 2026 |
Flatpak SystemHelper: CancelPull AbuseBy calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped. |
|
| CVE-2026-96281 | Sep 27, 2026 |
Flatpak Downgrade via Unprivileged RemoveLocalRef on Multi-user LinuxOn a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities. |
|
| CVE-2026-96280 | Sep 27, 2026 |
Flatpak OCI Delta Stream Parser Heap Overflow on 32-bit SystemsThe OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems. |
|
| CVE-2026-96279 | Sep 27, 2026 |
Flatpak Host File Disclosure via Hardlinking from Malicious OCI RegistryA malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow. |
|
| CVE-2026-91765 | Sep 25, 2026 |
PHP SOAP Unbounded Recursion Crash (SOAP XML Parser)cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper. |
|
| CVE-2026-6103 | Sep 25, 2026 |
Phar TAR Header Size Overflow Enables Content Injection in PHP Pharphar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine. |
|
| CVE-2026-93682 | Sep 25, 2026 |
PHP HTTP Stream Wrapper Redirect OOB Byte ExploitWhen the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory. |
|
| CVE-2026-93834 | Sep 25, 2026 |
Use-after-Free in QEMU 9pfs Enables VM EscapeA use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user. |
And others... |
| CVE-2026-96448 | Sep 25, 2026 |
Keycloak FGAP v2 PrivEsc via Composite Role LeakA flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm. |
|
| CVE-2026-97846 | Sep 25, 2026 |
Keycloak STX v2 Bypass mTLS HoK Binding for Token UseKeycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchange V2 feature does not check for this certificate. This allows an attacker with stolen client credentials to obtain a standard, unrestricted token that bypasses these security protections. |
|
| CVE-2026-94281 | Sep 24, 2026 |
Out-of-Bounds Read in libXi XListInputDevices() before 1.8.4An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. |
|
| CVE-2026-93545 | Sep 24, 2026 |
Out-of-Bounds Read in libXi <1.8.4 XListInputDevices CrashAn out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. |
|
| CVE-2026-93544 | Sep 24, 2026 |
LibXi OOB Read via XIQueryDevice before 1.8.4An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client. |
|
| CVE-2026-93543 | Sep 24, 2026 |
libXi <1.8.4 OOB Read in XI2 Class ParserAn out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. |
|
| CVE-2026-93542 | Sep 24, 2026 |
Out-of-Bounds Read in libXi (before 1.8.4) via XI2 Class ParsingAn out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client. |
|
| CVE-2026-93541 | Sep 24, 2026 |
Out-of-bounds read in libXi XQueryDeviceState (<1.8.4)An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a |
|
| CVE-2026-90959 | Sep 24, 2026 |
Red Hat Pulp Core Path Traversal via file_url in Content Upload APIA path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double slashes, creating a mismatch between what is validated and what is dispatched to the file downloader. An authenticated user with low-privilege repository permissions can supply a specially crafted URL using relative path traversal sequences to read any file accessible to the Pulp server process. In deployments that include Pulp Container, successful exploitation allows an attacker to read the container registry token signing private key and forge bearer tokens, granting unauthorized access to all private container repositories in the affected registry. |
And others... |
| CVE-2026-77874 | Sep 24, 2026 |
IBM Quarkus 3.27.1-3.27.5.SP1 SQL Injection VulnerabilityIBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. |
|
| CVE-2026-95521 | Sep 24, 2026 |
Command Injection via %() Macro in rpm SRPMA command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm. |
|
| CVE-2026-95519 | Sep 24, 2026 |
CVE-2026-95519: rpm manifest macro exp. allows RCEA flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account. |
|
| CVE-2026-94416 | Sep 24, 2026 |
Authorization Bypass in Red Hat Ansible Automation Platform GatewayAn authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary. |
|
| CVE-2026-97311 | Sep 24, 2026 |
Keycloak Admin REST API Bypass Group Visibility PermissionsA flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups. |
|
| CVE-2026-97185 | Sep 24, 2026 |
GIMP OOB Write via Malicious GIMPressionist PresetA flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. |
|
| CVE-2026-97177 | Sep 24, 2026 |
Keycloak Admin REST API Password Reset Bypass via User UpdateA flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account. |
|
| CVE-2026-97176 | Sep 24, 2026 |
Keycloak Auth Level Enforcement BypassA flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims. |
|
| CVE-2026-75887 | Sep 23, 2026 |
OpenShift Console Path Traversal via lng/ns on /locales/resource.jsonA flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends. |
|
| CVE-2026-75886 | Sep 23, 2026 |
OpenShift Console CatalogdHandler Auth Bypass & Cookie ForwardingA flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the disclosure of the internal operator-catalog index and providing a relay into the openshift-catalogd namespace. |
|
| CVE-2026-84724 | Sep 23, 2026 |
Arg Injection in Ansible Automation Platform Automation Controller System-JobAn argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments including Python's path option into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution. |
And others... |
| CVE-2026-84721 | Sep 23, 2026 |
SSRF in Ansible Automation Platform Email Backend Enables Internal Port ScanA server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback, link-local, or reserved address. An authenticated user with organization notification-admin permission can create or modify an email notification template pointing at an arbitrary internal address, trigger a test, and have the controller task process open a raw TCP connection to that address. The resulting connection error is reflected back through the notification record, providing a three-state internal port-scan oracle (open, closed, filtered) over the control-plane's cluster network, including the in-cluster Kubernetes API. When a shared organization template holds a stored SMTP password, redirecting the host can also cause that credential to be transmitted to an attacker-controlled server. |
|
| CVE-2026-84720 | Sep 23, 2026 |
Ansible Automation Platform: WorkflowJobNode DB Leak via Unfiltered ancestor_artifactsA flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST filter backend, even though it is omitted from the API serializer. Because the column is persisted before Ansible's no_log masking is applied, a user with only read access to a workflow or, via a regular-expression lookup that bypasses the JSON cross-relation filter guard through the world-readable credential-types endpoint, any authenticated user with no roles can use the result count as a boolean/count oracle to recover, character by character, secret values that a playbook author explicitly marked no_log, including across organizations. |
And others... |
| CVE-2026-84718 | Sep 23, 2026 |
Ansible Automation Platform: X-Forwarded-For Header Trust (CVE-2026-84718)A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access. |
And others... |
| CVE-2026-84717 | Sep 23, 2026 |
Ansible Platform: Unauth Bitbucket DC Webhook HMAC Bypass ID EnumerationA flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key. |
And others... |
| CVE-2026-84716 | Sep 23, 2026 |
Red Hat Automation Controller: TLS Impersonation via Case-Insensitive HostnameA flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments where the customer holds controller superuser but the platform operator runs the mesh this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle. |
And others... |
| CVE-2026-84713 | Sep 23, 2026 |
Red Hat Automation Controller: Cleartext Recipient Secret Leak via NotificationA flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text into the unprotected Notification.recipients field on every send. Because the credential-types endpoint is listable by any authenticated user and the API filter backend traverses object relations without per-hop authorization, a user with no privileges can use a relational filter as a boolean count-oracle to recover, character by character and across organizations, the secret recipient values of other tenants' notifications including PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook bearer-token URLs. This flaw affects confidentiality. |
|
| CVE-2026-84712 | Sep 23, 2026 |
Red Hat Automation Controller: /api/v2/ping over-serializes inventoryA flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the full instance inventory (node hostnames, node types, UUIDs, heartbeats, capacities, and exact versions), all instance-group names and membership, the deployment install UUID, and the active control node. A remote, unauthenticated attacker can use this to map the control plane and fingerprint software versions for targeted attacks. This flaw affects confidentiality only; it does not expose secrets, credentials, or tenant data. |
And others... |
| CVE-2026-96889 | Sep 23, 2026 |
Use-After-Free in librsvg via nested XInclude duplicate entitiesA flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code. |
|
| CVE-2026-85475 | Sep 23, 2026 |
Ansible Platform rsyslog RainerScript Injection Remote Code ExecutionA flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE into an rsyslog RainerScript config file without neutralizing RainerScript syntax. A privileged (superuser) user can inject rsyslog directives, including an omprog action, causing arbitrary command execution inside the control-plane rsyslog component. This allows disclosure of the controller SECRET_KEY and database credentials, decryption of all stored credentials, and full compromise of the control plane. |
|
| CVE-2026-84719 | Sep 23, 2026 |
Ansible: Workflow Copy Bypass InstanceGroup Auth (CVE-2026-84719)A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use including the control-plane instance group bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context. |
And others... |
| CVE-2026-84714 | Sep 23, 2026 |
Ansible Automation Platform Jinja Injection via sanitize_jinja()A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitize_jinja() is the sole guard on several launch-time fields ad-hoc command module_args, Machine-credential username / become_method / become_user, and inventory host names a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's AD_HOC_COMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary. |
And others... |