Database/Control plane, storage & DevOps
Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector): The custom Credential
Impact
The custom Credential Type environment-variable injector filters variable names with a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that leaves out loader and process-hijacking variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged AAP user can drop an attacker-controlled script into the execution environment and point BASH_ENV at it, gaining arbitrary code execution inside the execution-environment container for every job that attaches a credential of that type. Where AAP drives fleet provisioning, that container typically holds the credentials that reach GPU nodes, BMCs and switches, so the blast radius is the automation tier's whole credential set rather than one job. Scope is changed in the CVSS vector for exactly that reason. Affects AAP 2.5 (RHEL 8 and 9), 2.6 and 2.7.
Who can reach it
An authenticated AAP user privileged enough to define a custom Credential Type, over the network. Not reachable by an unprivileged user or an unauthenticated caller.
What to do
Apply the Red Hat errata for your stream (RHSA-2026:71113, 71114, 71177, 71179) and restart automation-controller. Until patched, audit existing custom Credential Types for injector entries setting loader variables and restrict who holds Credential Type authoring rights. No node or fleet maintenance window is needed - this is a control-plane service update.
References
Related entries
- OpenZFS (sharenfs export generation): When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silentlyCVE-2013-20001 · OpenZFS (sharenfs export generation)High
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardCVE-2018-12922 · Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm)High
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteCVE-2018-7185 · ntpd (protocol engine, zero-origin timestamp)High
- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedCVE-2019-10222 · Ceph RADOS Gateway (RGW, Beast frontend)High
- Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningCVE-2019-19728 · Slurm (srun --uid)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.