A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade receptor-debugsourceUpgrade automation-gateway-proxy-serverUpgrade python3.12-django-ansible-base+api_documentationUpgrade receptorUpgrade python3.12-django-ansible-baseUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-gateway-configUpgrade automation-platform-uiUpgrade automation-eda-controllerUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade automation-eda-controller-baseUpgrade python3.12-django-ansible-base+authenticationUpgrade receptor-debuginfoUpgrade automation-controllerUpgrade aap-metrics-utilityUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-gitpythonUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-gateway-serverUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-gateway-proxy-debugsourceUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-django-ansible-base+activitystreamUpgrade receptorctlUpgrade automation-gatewayUpgrade python3-sqlparseUpgrade automation-hubUpgrade automation-controller-serverUpgrade python3.12-galaxy-ngUpgrade automation-eda-controller-base-servicesUpgrade automation-controller-uiUpgrade python3.12-sqlparseUpgrade automation-controller-cliUpgrade automation-gateway-proxyUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-controller-venv-towerUpgrade python3.12-django-ansible-base+resource_registry | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub