PatchSiren cyber security CVE debrief
CVE-2026-89091 Red Hat CVE debrief
A flaw in ansible-core allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node with the privileges of the user running ansible-galaxy. This issue is a bypass of the fix for CVE-2020-10691. The vulnerability arises from the archive extractor validating member paths using lexical path normalisation instead of resolving symbolic links, and performing no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory.
- Vendor
- Red Hat
- Product
- Ansible Automation Platform 2
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
System administrators and security teams responsible for managing ansible-galaxy installations and ensuring the security of control nodes should assess their exposure and implement necessary security controls. They should review and update ansible-galaxy installations, implement additional security controls, and assess the exposure of control nodes running ansible-galaxy to potential exploitation.
Why it matters
CVE-2026-89091 is a high-severity vulnerability in ansible-core that allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node. System administrators and security teams should assess their exposure and implement necessary security controls.
- Potential arbitrary file writes on the control node.
- Potential code execution on the control node.
- Bypass of the fix for CVE-2020-10691.
- Need to verify affected versions and apply patches or mitigations.
Technical summary
The ansible-core flaw allows an attacker to install a malicious collection, potentially leading to arbitrary file writes and code execution on the control node. This issue bypasses the fix for CVE-2020-10691. The vulnerability arises from the archive extractor validating member paths using lexical path normalisation instead of resolving symbolic links, and performing no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the .
Defensive priority
High
Recommended defensive actions
- Review and update ansible-galaxy installations to ensure only trusted collections are used.
- Implement additional security controls to monitor and restrict ansible-galaxy usage.
- Assess exposure of control nodes running ansible-galaxy to potential exploitation.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE Program record and NVD vulnerability detail provide information on the flaw in ansible-core. The source item from cve_program_cvelist_v5 offers additional context on the vulnerability. Evidence is limited to public CVE Program and NVD records. Defenders should verify affected versions, apply patches or mitigations, and monitor for potential exploitation attempts. No additional facts are known.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89091 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89091
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89091 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89091
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitra
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89091.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-89091
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.