OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84691

HIGH · CVSS 8.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability in the Red Hat Ansible Automation Platform's automation-controller allows authenticated administrators to exploit a format-string template for API 4XX error logs, potentially exposing sensitive information such as the Django secret key and database password. This flaw enables attackers to access the master encryption key, facilitating offline decryption of stored credentials and unauthorized access to the controller database. Organizations using this platform should prioritize remediation to protect against potential credential theft and session forgery.

CVE
CVE-2026-84691
Severity
HIGH
CVSS
8.7
EPSS
0.20%

Original NVD Description

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.