PatchSiren cyber security CVE debrief
CVE-2026-84470 Red Hat CVE debrief
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.
- Vendor
- Red Hat
- Product
- Red Hat Ansible Automation Platform 2
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-04
Who should care
Administrators and users of Ansible Automation Platform's automation-controller (AWX), especially those with read-level permissions on instance groups and execute permissions on job templates. Operators and security teams should review instance group permissions and ensure use-level access is granted only to authorized users. Vulnerability management teams should monitor bulk job launch API usage for suspicious activity and implement compensating controls to restrict execution-placement isolation bypass if necessary. Platform teams should review and update instance group permissions to ensure use-level access is granted only to authorized users and implement compensating controls to restrict execution-placement isolation bypass if necessary. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory teams should review relevant monitoring, detection, and logs for exposed assets that need extra review. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Source tracking teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Teams should check relevant monitoring, detection, and logs for exposed assets that need extra review and implement compensating controls to restrict execution-placement isolation bypass if necessary. Teams should also review compensating controls for exposed systems while remediation is scheduled and verified and track exceptions, retest remediated assets, and close the item only after evidence is documented. Teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Teams should review and update instance group permissions to ensure use-level is
Technical summary
The Bulk Job Launch API in Ansible Automation Platform's automation-controller (AWX) has a flaw that allows users with read-level permission on instance groups to launch bulk jobs, bypassing execution-placement isolation. This requires execute permission on a job template. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. The flaw was found in Ansible Automation Platform's automation-controller (AWX). A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use.
Defensive priority
Medium-severity vulnerability in Ansible Automation Platform's automation-controller, allowing unauthorized bulk job launches with read-level permissions.
Recommended defensive actions
- Review and update instance group permissions to ensure use-level access is granted only to authorized users.
- Monitor bulk job launch API usage for suspicious activity.
- Implement compensating controls to restrict execution-placement isolation bypass.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Limited information is available from other sources. The Bulk Job Launch API in Ansible Automation Platform's automation-controller (AWX) has a flaw that allows users with read-level permission on instance groups to launch bulk jobs, bypassing execution-placement isolation. This requires execute permission on a job template. Administrators should review instance group permissions and ensure use-level access is granted only to authorized users. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84470 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84470
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84470 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84470
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-84470
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.