Bug 2527121 (CVE-2026-84678)

Summary: CVE-2026-84678 automation-controller: automation-controller-container: automation-controller: GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in ...
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The GALAXY_TASK_ENV setting, whose values are added to the environment of the ansible-galaxy commands run during project updates, is not validated to exclude dynamic-linker and interpreter environment variables such as LD_PRELOAD and PYTHONPATH, unlike the sibling AWX_TASK_ENV setting. A user with the system administrator role can set these variables to point at a file placed inside a project checkout on the shared projects volume, causing arbitrary native or Python code to execute inside the project synchronization execution environment on the control plane. This yields read and write access to every organization's project content and to injected Galaxy server tokens, resulting in a cross-tenant compromise of the automation content supply chain.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-09-01 21:59:43 UTC
A flaw was found in automation-controller (AWX). The AWX_TASK_ENV setting is
protected by a validator that rejects environment-variable keys which manipulate
dynamic linkers or interpreters (LD_*, DYLD_*, PYTHON*, PERL5OPT). The sibling
GALAXY_TASK_ENV setting (awx/main/conf.py) is registered as a bare KeyValueField
with no such validator. Its value is passed verbatim into project-update
extra_vars (awx/main/tasks/jobs.py RunProjectUpdate.build_extra_vars_file ->
'galaxy_task_env') and injected into the environment of the ansible-galaxy
command tasks in awx/playbooks/project_update.yml (environment: "{{
galaxy_task_env | combine(additional_galaxy_env) }}"). A system administrator
can set GALAXY_TASK_ENV to include LD_PRELOAD or PYTHONPATH referencing a file
in a project checkout under the shared /var/lib/awx/projects volume, achieving
arbitrary code execution inside the project-sync execution environment on the
control-plane task pod on the next sync of any project with a requirements file.
The container has read/write access to all organizations' checked-out project
source and to injected ANSIBLE_GALAXY_SERVER_*_TOKEN values, enabling cross-
tenant tampering and token theft, and constitutes a bypass of the linker/
interpreter blocklist AWX enforces on AWX_TASK_ENV. Note: in ansible/awx
upstream (devel) neither AWX_TASK_ENV nor GALAXY_TASK_ENV currently carries the
blocklist -- the AWX_TASK_ENV control is a downstream patch; both must be
present upstream to prevent regression. Discovered internally; verified live on
AAP 2.7 / automation-controller 4.8.1.
    Upstream: github.com/ansible/awx (awx/main/conf.py GALAXY_TASK_ENV;
              awx/main/tasks/jobs.py RunProjectUpdate.build_extra_vars_file;
              awx/playbooks/project_update.yml)

Comment 3 Jon Orris 2026-09-23 21:07:45 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114