GPU VulnDB

Database/Control plane, storage & DevOps

Ansible automation-controller: copied workflows keep instance groups, letting a tenant run jobs on the control plane

CVSS 9.9CVE-2026-84719Control plane, storage & DevOpscurated

Impact

Copying a WorkflowJobTemplate sanitizes only inventory, unified_job_template and credentials on each cloned node; instance_groups, execution_environment and labels are carried over from the original unchecked. A user who holds organization workflow-admin but no role on the referenced instance groups can copy a workflow, become its admin, and launch jobs pinned to instance groups they were never granted - including the control-plane instance group. On a fleet where automation-controller drives GPU node provisioning, driver rollout and drain/reboot orchestration, that means attacker-influenced playbooks execute in the control-plane execution context with whatever credentials and network reach that context has, which is generally the whole fleet. Red Hat rates it 9.9 with a scope change, and it needs only a low-privilege authenticated account.

Who can reach it

Authenticated automation-controller user with organization workflow-admin permission, over the network on whatever interface the controller UI/API is published on. No role on the target instance group is required - that is the boundary being bypassed.

What to do

Apply the automation-controller errata for your AAP stream (RHSA-2026:71113/71114/71115/71177/71179) and restart the controller services; this is a service-restart on the control-plane hosts, not a fleet-wide reboot. Until patched, audit who holds organization workflow-admin, review existing copied workflows for instance_groups they should not reference, and consider removing the control-plane instance group from templates that ordinary users can copy.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.