Database/Control plane, storage & DevOps
Ansible automation-controller: copied workflows keep instance groups, letting a tenant run jobs on the control plane
Impact
Copying a WorkflowJobTemplate sanitizes only inventory, unified_job_template and credentials on each cloned node; instance_groups, execution_environment and labels are carried over from the original unchecked. A user who holds organization workflow-admin but no role on the referenced instance groups can copy a workflow, become its admin, and launch jobs pinned to instance groups they were never granted - including the control-plane instance group. On a fleet where automation-controller drives GPU node provisioning, driver rollout and drain/reboot orchestration, that means attacker-influenced playbooks execute in the control-plane execution context with whatever credentials and network reach that context has, which is generally the whole fleet. Red Hat rates it 9.9 with a scope change, and it needs only a low-privilege authenticated account.
Who can reach it
Authenticated automation-controller user with organization workflow-admin permission, over the network on whatever interface the controller UI/API is published on. No role on the target instance group is required - that is the boundary being bypassed.
What to do
Apply the automation-controller errata for your AAP stream (RHSA-2026:71113/71114/71115/71177/71179) and restart the controller services; this is a service-restart on the control-plane hosts, not a fleet-wide reboot. Until patched, audit who holds organization workflow-admin, review existing copied workflows for instance_groups they should not reference, and consider removing the control-plane instance group from templates that ordinary users can copy.
References
Related entries
- GitLab EE: Duo Chat GraphQL subscription leaks Advanced Search config and credentialsCVE-2026-87719 · GitLab EE (Duo Chat GraphQL subscription argument handling)Critical
- lldpd (lldp_decode, management addresses): Buffer overflow in lldpd's LLDP decoder via large management addressesCVE-2015-8011 · lldpd (lldp_decode, management addresses)Critical
- Lantronix xPrintServer: The device ships with a hardcoded root account baked into every unit of a given firmware lineCVE-2016-4325 · Lantronix xPrintServerCritical
- HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoSCVE-2016-4375 · HPE iLO3 / iLO4Critical
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.