Red Hat Ansible Automation Platform: format string
High8.7CVE-2026-84691 · Published Sep 23, 2026 · updated Sep 24, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.
Affected versions
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-134
- www.cve.org/CVERecord?id=CVE-2026-84691
- nvd.nist.gov/vuln/detail/CVE-2026-84691
- access.redhat.com/errata/RHSA-2026:71113
- access.redhat.com/errata/RHSA-2026:71114
- access.redhat.com/errata/RHSA-2026:71177
- access.redhat.com/errata/RHSA-2026:71179
- access.redhat.com/security/cve/CVE-2026-84691
- bugzilla.redhat.com/show_bug.cgi?id=2527151
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Red Hat OpenShift Container Platform 4: path traversal | High7.5 | No fix yet |
| Sep 23 | Red Hat OpenShift Container Platform 4: attacker could send requests | High7.2 | No fix yet |
| Sep 23 | Red Hat librsvg.: use after free | High7.8 | No fix yet |
| Sep 23 | Red Hat: argument injection | Medium6.6 | No fix yet |
| Sep 23 | A flaw was found in the Ansible Automation Platform automation controller | High7.2 | No fix yet |
| Sep 23 | Red Hat: incomplete denylist | High7.1 | No fix yet |