GPU VulnDB

Database/Control plane, storage & DevOps

Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manage

CVSS 6.6CVE-2026-84724Control plane, storage & DevOpscurated

Impact

The system-job launch endpoint stores a user-supplied days value without the integer validation defined for that field, and the dispatcher joins management-command arguments into one space-separated string before the runner re-splits it, so spaces become extra command-line arguments. System jobs run in-process on the control node without the container isolation applied to every other job type, so the injected arguments land in the control-plane awx-manage process and can control its argument vector and the first entry of its Python module search path. Red Hat notes that full remote code execution needs an import gadget not present in the current management commands, so the demonstrated impact is argument injection with search-path control, not confirmed execution. For an operator using AAP to drive fleet configuration, a compromise of the control node reaches every managed GPU host, which is why the CVSS vector marks scope changed.

Who can reach it

Network-reachable automation-controller API, authenticated as a superuser. That is a high-privilege account already, which is why the score stays moderate - the value is the escape from the container isolation that constrains normal jobs.

What to do

Apply the automation-controller errata (RHSA-2026:71113, 71114, 71177, 71179) for your AAP 2.5/2.6/2.7 channel and restart the controller services; no managed-node reboot or fleet drain is needed. Until patched, keep the superuser population minimal and audited, since that is the only precondition.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.