A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments — where the customer holds controller superuser but the platform operator runs the mesh — this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade aap-metrics-utilityUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-django-ansible-base+rest_filtersUpgrade python3.12-galaxy-ngUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-gitpythonUpgrade automation-gateway-proxy-debugsourceUpgrade automation-controllerUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-eda-controllerUpgrade automation-platform-uiUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-eda-controller-base-servicesUpgrade automation-gateway-proxy-serverUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade receptor-debugsourceUpgrade automation-gateway-configUpgrade automation-gatewayUpgrade receptorUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-controller-serverUpgrade python3.12-django-ansible-baseUpgrade python3-sqlparseUpgrade automation-controller-venv-towerUpgrade receptor-debuginfoUpgrade automation-gateway-serverUpgrade python3.12-django-ansible-base+activitystreamUpgrade automation-controller-uiUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-hubUpgrade automation-eda-controller-baseUpgrade automation-eda-controller-worker-servicesUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3.12-django-ansible-base+resource_registryUpgrade python3.12-sqlparseUpgrade automation-gateway-proxyUpgrade receptorctl | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub