OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84714

HIGH · CVSS 7.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability exists in the input-validation mechanism of the automation controller, specifically within the sanitize_jinja() function, which inadequately filters user-supplied Jinja expressions. This flaw allows low-privileged users to inject malicious Jinja code, potentially executing arbitrary commands and disclosing sensitive credential information in the execution environment. Organizations utilizing this automation controller should prioritize patching this vulnerability to mitigate risks associated with unauthorized command execution and credential exposure.

CVE
CVE-2026-84714
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitize_jinja() is the sole guard on several launch-time fields — ad-hoc command module_args, Machine-credential username / become_method / become_user, and inventory host names — a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's AD_HOC_COMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary.