PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89091 Red Hat CVE debrief

A flaw in ansible-core allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node with the privileges of the user running ansible-galaxy. This issue is a bypass of the fix for CVE-2020-10691. The vulnerability arises from the archive extractor validating member paths using lexical path normalisation instead of resolving symbolic links, and performing no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory.

Vendor
Red Hat
Product
Ansible Automation Platform 2
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

System administrators and security teams responsible for managing ansible-galaxy installations and ensuring the security of control nodes should assess their exposure and implement necessary security controls. They should review and update ansible-galaxy installations, implement additional security controls, and assess the exposure of control nodes running ansible-galaxy to potential exploitation.

Why it matters

CVE-2026-89091 is a high-severity vulnerability in ansible-core that allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node. System administrators and security teams should assess their exposure and implement necessary security controls.

  • Potential arbitrary file writes on the control node.
  • Potential code execution on the control node.
  • Bypass of the fix for CVE-2020-10691.
  • Need to verify affected versions and apply patches or mitigations.

Technical summary

The ansible-core flaw allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node. This issue bypasses the fix for CVE-2020-10691. The vulnerability arises from the archive extractor validating member paths using lexical path normalisation instead of resolving symbolic links, and performing no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the .

Defensive priority

High

Recommended defensive actions

  • Review and update ansible-galaxy installations to ensure only trusted collections are used.
  • Implement additional security controls to monitor and restrict ansible-galaxy usage.
  • Assess exposure of control nodes running ansible-galaxy to potential exploitation.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE Program record and NVD vulnerability detail provide information on the flaw in ansible-core. The source item from cve_program_cvelist_v5 offers additional context on the vulnerability. Evidence is limited to public CVE Program and NVD records. Defenders should verify affected versions, apply patches or mitigations, and monitor for potential exploitation attempts. No additional facts are known.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89091 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89091

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89091 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89091

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.